Cloud credential access shortly after terraform provider execution
Detects the execution of terraform.exe or go.exe on developer hosts, which acts as a precursor to the malicious Terraform provider campaign (Graphalgo) that targets cloud credentials.
Microsoft Sentinel (KQL)

