drop gcs data-access audit log · parse object reads + writes
flags objects.get bursts · bucket IAM changes · public ACL grants · off-hours · actor spikes · bulk destructive
heuristic screener · client/export format varies — column mapping is best-effort · filters storage.googleapis.com only · not definitive proof