Interlock-style LOLBin Abuse — ClickFix / Fake CAPTCHA -- PowerShell Download-Execute
Detects the execution of LOLBins (PowerShell, mshta, cmd, wscript) directly spawned from common web browsers (explorer, chrome, edge, firefox) with command-line arguments indicative of malicious activity, such as base64-encoded commands, hidden window styles, or remote script download and execution.
Microsoft Sentinel (KQL)

