Hello @mcn1k
Thank you for reaching out to the support community.
The rule is working as expected generating events for each access of the certutil.exe process.
If you would limit it to a specific event for the process you could generate less events, but also miss legitimate events you would be trying to catch if it doesn't meet all the requirements in the rule.
You can generate more consolidated reports to try and have a better visualization for those events as well.
Hope this was helpful.
Was my reply helpful?
If you find this post useful, Please give it a Kudos! Also, Please don't forget to select "Accept as a solution" if this reply resolves your query!
Thanks and regards,
Tiago A