ClickFix WebDAV-Hosted LNK/HTA Execution via DavWWWRoot Path
This rule detects the execution of LNK or HTA files from a WebDAV share (DavWWWRoot) using common Windows binaries like mshta.exe, wscript.exe, cscript.exe, or explorer.exe. This pattern is commonly associated with the 'ClickFix' technique, where users are lured into opening malicious files hosted on remote WebDAV shares to achieve code execution.
Sigma

