ClickFix-style browser-to-shell execution preceding Sauron Loader install
Detects a specific social-engineering pattern known as 'ClickFix' where a user is manipulated into opening the Windows Run dialog (explorer.exe) to manually execute commands. The rule identifies suspicious command-line arguments typically associated with initial access (e.g., PowerShell hidden/encoded execution, web downloads) followed by the execution of MSI installers or related malicious binaries (e.g., rnpkeys.exe) within a 30-minute window, indicative of the Sauron Loader infection chain.
Microsoft Sentinel (KQL)

