ClickFix LoLBin Abuse
This rule detects suspicious command-line activity involving several Windows executables (wscript.exe, cscript.exe, wmic.exe, ssh.exe) when combined with specific keywords. It looks for wscript.exe or cscript.exe executing 'SyncAppvPublishingServer.vbs', wmic.exe executing 'process', 'call', or 'create', or ssh.exe using 'ProxyCommand'. Additionally, the rule filters for command lines containing keywords like 'gal', 'i*x', 'gcm', '*stM*', 'jsdelivr.net', 'github', or 'powershell', which are often associated with malicious activity, obfuscation, or external resource loading.
Microsoft Sentinel (KQL)

