Help with rules to detect TLS/HTTPS traffic that is using untrusted CA

Can you post-process something after doing tls_store ?