Suspicious certutil.exe LOLBIN usage (encode/decode/urlcache/store)

This rule detects the use of the Windows certutil.exe utility with flags commonly abused by adversaries for file downloads (-urlcache, -urlfetch) or file deobfuscation/decoding (-decode, -decodehex, -encode). It specifically targets LOLBIN (Living Off the Land Binary) behavior by monitoring process command line arguments, while providing allowances for common administrative tasks like PKI maintenance or CRL/OCSP updates to minimize false positives.