Suspicious GCP Service Account Interaction with Google APIs
This rule detects potentially malicious interaction with specific GCP service account identifiers and client IDs. It monitors multiple log sources—including cloud audit logs, sign-in activity, security logs, and device network events—to identify unauthorized access, command and control communication, or data exfiltration attempts targeting Google API services (specifically oauth2.googleapis.com and sheets.googleapis.com).
Microsoft Sentinel (KQL)

