Possible STRD OAuth Authorization Code Theft - accounts.google.com Request Missing Security Parameters

This rule detects suspicious Google OAuth authorization requests directed at accounts.google.com that utilize a local redirect URI (http://localhost) and are missing mandatory security parameters such as code_challenge, state, and login_hint. These characteristics are often associated with OAuth-based phishing or credential theft campaigns where an adversary attempts to intercept authorization codes.