CertUtil LOLBin Abuse: Remote Download or Payload Decode

This rule monitors for potentially malicious use of the Windows Certutil utility, specifically targeting the -urlcache (often used to download remote files) and -decode (used to decode hidden or obfuscated payloads) command-line arguments. It filters out common trusted processes like Microsoft's msiexec.exe to reduce noise.