Suspicious Execution of Living-Off-the-Land Binaries from Browser Parent via Weaponized Clip-Paste Technique
A detection triggered on endpoint events where common system binaries (e.g., mshta.exe, powershell.exe, cmd.exe) were launched by user-facing parent processes (explorer.exe, chrome.exe, msedge.exe, firefox.exe, iexplore.exe) and executed suspicious command-lines. The pattern matches the evolving technique used in ClickFix-style campaigns whereby malicious pages dynamically place payloads into the clipboard and prompt users to paste or execute them.
Microsoft Sentinel (KQL)

