Cloud CLI Credential File Access by Non-Standard Process (AWS/Azure/GCP)
Detects unauthorized or non-standard processes attempting to create, modify, or access sensitive cloud configuration and credential files, such as AWS credentials, Azure CLI token caches, or GCP application default credentials. This behavior is indicative of potential credential theft or unauthorized access to cloud environment tokens.
SentinelOne

