ClickFix Lure - Browser Spawning Script Interpreter with Malicious Cmdline
Detects ClickFix social engineering lures where a web browser spawns script interpreters (cmd.exe, powershell.exe, or mshta.exe) with command-line arguments indicative of malicious activity, such as base64-encoded payloads, remote download cradles, or execution with hidden window flags.
Sigma

