ClickFix: PowerShell Reflective .NET Load Combined With Obfuscation Indicators
Detects execution of PowerShell commands that exhibit characteristics frequently associated with malicious activity, such as reflective assembly loading, compression/decompression operations, use of specific known obfuscation markers, encoded commands, or execution originating from suspicious parent processes like explorer.exe or cmd.exe.
Microsoft Sentinel (KQL)

