ClickFix - Encoded PowerShell Spawned from explorer.exe or cmd.exe
Detects the execution of PowerShell with an encoded command flag when spawned directly from explorer.exe or cmd.exe. This pattern is frequently used in 'ClickFix' style attacks where users are tricked into copying and pasting malicious, obfuscated PowerShell code into the Windows run dialog or command prompt.
SentinelOne

