LOLBAS Exfil via certutil or bitsadmin to External Destination

Detects the use of legitimate Windows binaries (Certutil and BITSAdmin) to communicate with external, non-Microsoft IP addresses, which is indicative of potential tool downloading or data exfiltration. The rule explicitly filters out known Microsoft update domains to reduce noise.