ClickFix: LOLBins Spawned by explorer.exe via Run Dialog or Clipboard
Detects the execution of known living-off-the-land binaries (LOLBins) such as mshta.exe, certutil.exe, bitsadmin.exe, wscript.exe, or cscript.exe directly by explorer.exe. This pattern is indicative of a user-initiated execution, potentially triggered by social engineering lures like the 'ClickFix' technique, where a user is tricked into pasting and running malicious commands in the Windows Run dialog or a command prompt context.
SentinelOne

