Certutil.exe Decode or Download to Suspicious Directory

Detects the use of the built-in Windows utility 'certutil.exe' with arguments commonly used to download remote content (-urlcache -split -f) or decode base64 encoded files (-decode, -decodehex), when the output or operation occurs within temporary system directories such as Temp, AppData, or ProgramData, and the process is not signed by Microsoft.