Suspicious Remote Write to Certificate Services Log Directory

Detects unauthorized remote write operations (via SMB, Named Pipes, or TCP) to the Windows Certificate Services CertLog directory (C:\Windows\System32\CertLog\). This directory contains sensitive CA database, transaction logs, and checkpoint files. Any modification by a process other than the legitimate certsvc.exe is indicative of potential CA database tampering, malicious log manipulation, or anti-forensics activity.