certutil.exe LOLBin Abuse for Payload Download and Decode Staging

Detects usage of the Windows certutil.exe binary to perform potentially malicious operations such as downloading files via URL cache or decoding base64/hex payloads. The rule specifically alerts when these actions occur within common user-writable or temporary directories often used by threat actors for file staging.