macOS ClickFix - Browser/Mail Shell Spawn, DMG Download, and Infostealer Execution
This rule detects a multi-stage attack chain on macOS involving a browser or mail client spawning a shell to download a file (DMG) via curl/wget, followed by the mounting of that disk image, execution of an application bundle from the mounted volume, and a subsequent outbound network connection from that application. This behavior is indicative of a user-initiated malware execution chain.
Microsoft Sentinel (KQL)

