ClickFix: mshta/powershell Run-dialog exec with download cradle after CAPTCHA
This rule detects potentially malicious command-line activity involving powershell.exe or mshta.exe that is initiated by a web browser process (chrome.exe, msedge.exe, firefox.exe, or iexplore.exe). It monitors for indicators such as encoded commands, usage of Invoke-Expression, download cradles, hidden window flags, and specific known IOCs, correlating these events with recent browser activity to identify potential drive-by download or browser-based exploitation attempts.
Microsoft Sentinel (KQL)

