ClickFix Fake CAPTCHA (cloudrobots.cloud) Clipboard Command Execution
Detects ClickFix-style social engineering attacks where users are lured to 'cloudrobots.cloud' and subsequently execute malicious commands via Windows shell tools (cmd, powershell, mshta, etc.). The rule correlates browser network events to a specific domain, subsequent process launches by explorer.exe, and suspicious registry modifications associated with the Windows RunMRU, which is often abused to store and execute commands pasted by victims.
Microsoft Sentinel (KQL)

