When I worked in a SOC I can't recall seeing anything malicious from them directed at my network -- it was usually AWS or Azure instances.
I'd focus on behaviors rather than providers -- I found them to be stricter than other providers at times when I was more of a skiddie -- I got very angry emails when I accidentally used an Algo I had set up on their stuff instead of a separate one for "linux ISOs".