Cloud Credential File Access by Non-Cloud-CLI Process

Detects file creation or modification events targeting sensitive cloud credential storage locations, such as AWS credentials files, Azure configurations, and Google Cloud credentials databases. The rule filters out known legitimate CLI tools, flagging potential unauthorized access or exfiltration of cloud credentials by other processes.