ClickFix Encoded PowerShell Loader Fetching Multiple Payloads
Detects potential ClickFix-style social engineering attacks where a victim is prompted to execute an encoded PowerShell command (often via copy-paste into a terminal). The rule specifically monitors PowerShell processes initiated by shell environments (explorer.exe, cmd.exe, or WindowsTerminal.exe) that execute encoded, hidden scripts to perform multiple suspicious network requests for files (e.g., .zip, .enc, .bin) from non-standard domains.
Microsoft Sentinel (KQL)

