Frequent SSL/TLS Command Line Activity

This rule detects when a process's command line contains 'ssl' or 'tls' and is observed at least 3 times within an hour on the same computer and by the same account. This could indicate various activities, including legitimate system processes, development activities, or potentially malicious use of SSL/TLS-related tools or scripts. The rule focuses on process creation events (EventID 4688) and analyzes the command line arguments.