ClickFix Series: DocuSign-Themed Lure Triggering Native Terminal Command Executi

Detects instances where cmd.exe or powershell.exe are launched from explorer.exe with command-line arguments containing DocuSign-themed keywords. This behavior is indicative of a 'ClickFix' phishing attack, where a user is socially engineered to copy and execute a malicious command via the terminal after interacting with a fraudulent DocuSign lookalike page.