Rogue Certificate Import into LocalMachine Root Trust Store

This rule monitors for suspicious activities involving digital certificates. It detects PowerShell processes attempting to import a certificate into the Root store, which could indicate persistence or credential interception, and it detects the use of curl to download files named 'cert.pem' with insecure SSL settings (no certificate verification).