macOS ClickFix: fake CAPTCHA clipboard command decoded and piped to bash
Detects execution of encoded commands in macOS terminal environments that originate from clipboard content mimicking a reCAPTCHA verification process. This pattern often involves users being social-engineered into pasting a malicious string that decodes a payload and pipes it directly into a shell interpreter (sh/bash/zsh). The rule monitors for the co-occurrence of base64/openssl decoding commands and shell execution pipes, while filtering out known legitimate software installation patterns.
Microsoft Sentinel (KQL)

