ClickFix Win+R execution via explorer.exe spawning script interpreter
Detects the execution of script interpreters (powershell, cmd, mshta, etc.) spawned directly by explorer.exe via the Run dialog, commonly associated with 'ClickFix' social engineering attacks where users are prompted to copy and paste malicious commands to bypass security mechanisms.
Microsoft Sentinel (KQL)

