Metasploit Meterpreter Reverse HTTPS C2 Self-Signed Bare Wildcard Cert

Detects TLS/SSL traffic patterns characteristic of Metasploit Meterpreter reverse HTTPS command-and-control communication, specifically targeting the use of default, self-signed certificates with a subject line containing a bare wildcard (CN=*) in the common name field, a common artifact of unconfigured Metasploit payloads.