Certificate Exported Via PowerShell — Detection Rule

Detects calls to cmdlets that are used to export certificates from the local certificate store. Threat actors were seen abusing this to steal private keys from compromised machines.

Read the full analysis on IntelFusions