Obfuscated PowerShell downloads configuration.ps1 via ClickFix (mnl.ac)
Detects obfuscated PowerShell commands bypassing execution policy to download or execute 'configuration.ps1' or communicate with known malicious infrastructure associated with the ClickFix campaign. The rule specifically looks for caret-based obfuscation, bypass switches, and known IOCs in the command line.
Splunk (SPL)

