ClickFix ZZ1984 marker: correlated PowerShell lookup + findstr + minimized cmd chain
Detects the DOUBLECUP/ClickFix loader activity which involves a sequence of suspicious command-line execution patterns. The rule correlates three specific behaviors occurring within a 5-minute window: finding PowerShell paths using 'where', searching for the 'ZZ1984' marker using 'findstr', and executing a minimized background command process. This combination is highly indicative of the ClickFix delivery chain used to trick users into running malicious commands.
Cortex XDR

