Cloud Secret Exfil via Env Variable Access from Unexpected Processes

Detects unauthorized processes, such as shells, scripting engines, or command-line utilities, that attempt to display or access environment variables containing sensitive cloud credential patterns (e.g., AWS_ACCESS, API_KEY). This behavior often indicates an attempt to steal cloud provider credentials from the host environment.