APT28 ClickFix Encoded PowerShell via mshta/wscript/cscript
Detects the execution of PowerShell with encoded commands initiated by common Windows script hosting utilities (mshta.exe, wscript.exe, or cscript.exe). This pattern is frequently used by adversaries to bypass execution policy restrictions or evade detection by proxying the execution of malicious payloads through legitimate, signed system binaries.
Microsoft Sentinel (KQL)

