Metasploit Meterpreter Reverse HTTPS C2 Default Cert and Port

Detects network traffic consistent with the Metasploit Meterpreter reverse HTTPS payload, specifically looking for the default 'CN=metasploit' certificate subject name used by the framework in SSL/TLS handshakes, or connections targeting default Meterpreter ports like 4444.