ClickFix - Browser Spawning Suspicious Script Interpreter

Detects instances where common web browsers (Chrome, Edge, Firefox, Brave) spawn command-line tools or script interpreters (cmd, PowerShell, wscript, mshta) as child processes. This behavior is highly indicative of drive-by download attacks, including the 'ClickFix' technique, where users are socially engineered into executing malicious commands under the guise of fake browser updates or error resolution.