https://arimboor.github.io/posts/DE-YARA-Hunt-Stolen-cert/
Part 4.1 - Hunting for files with Stolen code-signing Cert. - Investigation notes for Microsoft Windows Endpoints and Azure Cloud infrastructure