ClickFix Fake Decryption-Error Lure Spawns Shell/PowerShell from Browser
This rule detects potentially malicious command execution initiated by web browsers (Chrome, Edge, Firefox, Safari, Opera). It identifies scenarios where browsers spawn PowerShell on Windows with encoded command arguments or spawn shells (zsh, bash, sh) on macOS while piping commands retrieved via curl or wget, which is a common pattern for dropper and fileless malware delivery.
CQL

