Golden SAML: Token-Signing Cert Rotated/Exported Outside Schedule

This rule detects unscheduled modifications to federation, application, or service principal credentials, including ADFS token-signing certificates, in both Azure AD (via O365 management activity logs) and local Windows environments (via Security Event Logs). It filters these events against a known rotation schedule to highlight suspicious, non-routine changes that may indicate persistence establishment or identity provider tampering.