Ransomware Series: MSHTA Proxy Execution of Remote or Encoded HTA Payload
Detects instances where mshta.exe is launched from a web browser or explorer.exe with suspicious command-line arguments, such as remote URLs, script protocols, or potentially obfuscated/base64-encoded strings, often indicative of 'ClickFix' social engineering attacks.
Microsoft Sentinel (KQL)

