ClickFix: PowerShell spawned from browser downloads via WebDAV
Detects the execution of PowerShell with suspicious command-line arguments (e.g., WebClient, hidden flags, or WebDAV paths) spawned directly from browser processes like chrome.exe or msedge.exe. This pattern is commonly associated with fileless delivery techniques where an attacker attempts to download and execute scripts directly from an internet-facing source.
SentinelOne

