Anomalous cloud sign-in shortly after Vite secrets exfiltration attempt

Detects anomalous cloud authentication events occurring within a 3-hour window after suspected unauthorized access to sensitive configuration or credential files on a Vite development server. The rule flags sign-ins with high risk, anomalous location, or missing device compliance information, excluding trusted corporate locations and devices, serving as an indicator of potential post-exfiltration account takeover.