ClickFix: hidden-window base64 PowerShell via Run dialog (RunMRU)
This rule detects potentially malicious PowerShell activity executed from Windows Explorer with obfuscated arguments (-enc, -w hidden) in conjunction with access to the Windows RunMRU registry key, which tracks commands executed via the Windows Run dialog.
Microsoft Sentinel (KQL)

