Phishing Series 2026: ClickFix Payload Staging via finger.exe Ingress Tool Transfer

Detects the use of the 'finger.exe' utility in a suspicious manner, indicative of payload staging in a 'ClickFix' phishing attack scenario. The rule monitors for instances where 'finger.exe' is executed with suspicious command-line arguments (containing '@' or '-l') by common parent processes associated with malicious copy-paste activities (cmd.exe, powershell.exe, or explorer.exe).