ShieldCrash GUID staging dir + cloud provider co-registration

Detects suspicious file activity within directories named 'ShieldCrash' followed by a cloud provider registration or placeholder creation event within a 5-minute window. This behavior is indicative of unauthorized software or an adversary attempting to stage data for exfiltration or create persistent storage aliases outside of legitimate cloud client applications.