ClickFix Clipboard Paste IEX Execution - PowerShell IRm/IEX from Interactive Session
Detects the execution of PowerShell or pwsh that originates from an interactive parent process like explorer.exe or cmd.exe. The rule identifies suspicious command-line patterns containing 'IEX', 'Invoke-Expression', 'Invoke-WebRequest', 'iwr', or 'IRm', while excluding encoded commands, which is indicative of potential malicious clipboard-paste activity or manual attacker intervention.
Splunk (SPL)

