ClickFix: Explorer-Spawned Encoded PowerShell/MSHTA via Run Dialog

Detects suspicious command-line patterns originating from the Windows Explorer process (explorer.exe). This rule identifies the execution of various scripting engines or utilities like PowerShell, CMD, MSHTA, and WScript/CScript when they are used with potentially malicious flags or command-line arguments, including encoded commands, hidden window styles, web-download strings, or direct HTA/scripting invocations, which are common indicators of malicious activity following potential user execution.