Certificate File Creation or Modification

This rule detects the creation or modification of files that contain common certificate-related keywords such as 'crl', 'certificate', or 'pem'. This activity could indicate the deployment of new certificates, which might be legitimate or malicious, such as for establishing command and control, code signing, or evading detection.