ClickFix Lure Spawns finger.exe to Retrieve Staged Payload
This rule detects the execution of the legacy finger.exe utility when spawned by common user-facing applications (e.g., browsers, shells, explorer). The detection specifically looks for instances where the command line includes an '@' character, indicating an attempt to query information from a remote host, while excluding standard localhost queries. This pattern is often associated with reconnaissance activity or enumeration of remote users/systems.
SentinelOne

