ClickFix Lure Spawns Shell from Browser Process
Detects instances where a web browser process (e.g., Chrome, Edge, Firefox) spawns a command shell (cmd.exe) or PowerShell (powershell.exe). This pattern is frequently associated with malicious 'ClickFix' or 'fake decryption' social engineering campaigns where users are tricked into copying and executing malicious commands into a terminal.
Sigma

