CRPx0 ClickFix RunMRU Registry Trace - PowerShell/curl Run Dialog

This rule detects potentially malicious command execution by monitoring additions to the Windows Explorer RunMRU registry key. It specifically triggers when the registry data contains references to 'powershell', 'curl', or appears to be encoded/base64 strings, which are often used by adversaries to execute malicious scripts or download payloads via the Run dialog.