Rogue Root CA Installed via certutil -addstore for HTTPS Interception
Detects the use of certutil.exe to add a certificate to the root store. Adversaries may perform this action to establish persistence or facilitate interception of encrypted traffic by adding a malicious CA certificate to the trusted root store.
SentinelOne

