Suspicious OpenSSL or Certificate Activity
This rule detects suspicious activity related to OpenSSL or certificate manipulation by identifying processes that execute commands containing 'openssl' or 'certificate' keywords. It aggregates these activities by computer and account within one-hour bins and flags if three or more such activities occur, which could indicate credential access attempts or system misconfiguration.
Microsoft Sentinel (KQL)

