2026 Critical Enterprise Intrusion Chain Detection: Cloud CLI Credential Cache Theft (AWS SSO / kubeconfig / gcloud)

Detects non-CLI and non-DevOps utility processes accessing sensitive cloud credential and configuration files, including AWS SSO caches, AWS credentials, kubeconfig, and gcloud configuration files. This behavior is indicative of credential theft or discovery by infostealers attempting to gain unauthorized access to cloud environments.