Certutil Copied to Public Downloads and Used to Decode Base64 Blob

Detects suspicious execution of the certutil.exe utility for file operations, specifically targeting the copying of certutil or the decoding of files with naming patterns (kid*.exe, kid*.tmp, kid*.bat) within the \Users\Public\Downloads\ directory. This pattern is commonly associated with file staging and deobfuscation of malicious payloads.