macOS ClickFix Terminal launch with base64|bash reCAPTCHA lure
Detects instances where a user pastes and executes commands, specifically those containing reCAPTCHA verification strings or base64-encoded bash commands, within a macOS Terminal session. This behavior is indicative of a 'ClickFix' social engineering attack where a user is tricked into manually executing malicious commands in their shell.
Splunk (SPL)

