Malicious Browser-Initiated Clipboard Paste Execution T1204.004
Detects instances where common web browsers (chrome.exe, msedge.exe, firefox.exe, brave.exe, opera.exe) initiate command-line utilities (cmd.exe, powershell.exe, wscript.exe) that include arguments indicative of downloading remote resources (curl, iwr, Invoke-WebRequest, bitsadmin, certutil). This pattern is frequently used to download and execute second-stage malicious payloads.
Microsoft Sentinel (KQL)

