ClickFix PowerShell Loader Chain – Magecart Two-Stage Evasion

This rule monitors for specific PowerShell command-line patterns often associated with malicious activity, including 'ClickFix' clipboard-paste lures (using iex/irm with sleep timers), evasion techniques involving pscustomobject/ScriptBlock, and WinHttp COM object usage for stage-2 payload fetching. These patterns are characteristic of adversary attempts to bypass security controls and download secondary implants.