ShieldCrash GUID staging dir + cloud provider co-registration
Detects suspicious file activity within directories named 'ShieldCrash' followed by a cloud provider registration or placeholder creation event within a 5-minute window. This behavior is indicative of unauthorized software or an adversary attempting to stage data for exfiltration or create persistent storage aliases outside of legitimate cloud client applications.
Microsoft Sentinel (KQL)

