ClickFix Fake CAPTCHA: Browser Spawning mshta.exe or wscript.exe
This rule detects potentially malicious activity where a web browser (e.g., Chrome, Edge, Firefox) spawns suspicious child processes (e.g., mshta.exe, wscript.exe) with command-line arguments that include indicators of script execution, remote code download, or command invocation, which is a common pattern in drive-by download attacks and malicious link execution.
Microsoft Sentinel (KQL)

