ClickFix Series: LOLBin Download Cradle via curl.exe or certutil.exe From explor

Detects the use of legitimate Windows system binaries (LOLBins) such as curl.exe, certutil.exe, or bitsadmin.exe to download files. These binaries are monitored when spawned directly from common entry-point processes like explorer.exe, cmd.exe, or powershell.exe, which is characteristic of second-stage payload retrieval in ClickFix social engineering campaigns.