ClickFix PowerShell irm-cradle writing and executing script from %TEMP%
Detects the execution of PowerShell with a bypass execution policy that performs a download or web request to save content to a file in the user's temp directory, followed by the immediate execution of that file. This pattern is characteristic of multi-stage malware droppers or fileless attack techniques attempting to stage and execute malicious scripts from temporary locations.
Microsoft Sentinel (KQL)

