ClickFix PasteJack - Clipboard-Seeded Payload via Explorer or Browser (T1204.004)

Detects instances where common browser processes or Windows Explorer initiate suspicious child processes like cmd.exe, powershell.exe, or mshta.exe. The rule uses a scoring mechanism based on the presence of encoded command indicators, web-related payloads, or specific HTA script arguments to identify potentially malicious activity such as drive-by downloads or living-off-the-land execution.