Detection catalogue
Explore published rules with transparent provenance, licensing, and ATT&CK mappings.
- detections
Loading detections…
Loading detections
Explore published rules with transparent provenance, licensing, and ATT&CK mappings.
Loading detections…
Detects calls to cmdlets inside of PowerShell scripts that are used to export certificates from the local certificate store. Threat actors were seen abusing this to steal private keys from compromised machines.
Outside the enterprise matrix
Published to signed-in readers
The query as its source wrote it, its canonical form, and the content hash that pins this exact revision.