APT28 ClickFix Encoded PowerShell via mshta/wscript/cscript

Detects the execution of PowerShell with encoded commands initiated by common Windows script hosting utilities (mshta.exe, wscript.exe, or cscript.exe). This pattern is frequently used by adversaries to bypass execution policy restrictions or evade detection by proxying the execution of malicious payloads through legitimate, signed system binaries.