ClickFix: PowerShell spawned from Explorer/Browser via Win+R paste
Detects the execution of PowerShell with suspicious command-line arguments (hidden window, no profile, or encoded commands) spawned directly from a web browser process (e.g., Chrome, Edge, Firefox, Explorer). This behavior is characteristic of ClickFix-style social engineering attacks where a user is tricked into copying and executing malicious PowerShell commands via the Win+R Run dialog or terminal.
Splunk (SPL)

