We can create Shadow IT via Audit policies in Protect.
Cloudsoc 3.159
You can now create Shadow IT via Audit policies in Protect. You can build these policies using Audit filters such as service attributes and user attributes while setting the data sources, service types, policy evaluation frequency, and so on.
This has been added recently in the 3.159 CloudSOC release