ClickFix-style clipboard-pasted PowerShell launched via Run dialog from browser
Detects the 'ClickFix' technique where a user is socially engineered into copying a malicious command to their clipboard and pasting it into the Windows Run dialog (Win+R). The rule monitors for powershell.exe spawned by explorer.exe containing specific social engineering keywords or typical fileless download-execute patterns like 'irm', 'iex', or 'Invoke-RestMethod'.
Microsoft Sentinel (KQL)

