Suspicious Authentication Certificate and Private-Key Export Activity
This Defender XDR query detects high-confidence attempts to export certificates with private keys using native Windows utilities, PowerShell, Mimikatz, AADInternals, Certipy, OpenSSL, and certificate-management tools.
Microsoft Sentinel (KQL)

