ClickFix Social Engineering - Clipboard-to-Run Execution Chain

Detects ClickFix-style attacks where a user is tricked into copying and pasting malicious, often obfuscated, commands into the Windows Run dialog or a command prompt. The detection identifies suspicious parent processes (like explorer.exe) spawning shell interpreters (powershell.exe, cmd.exe, mshta.exe) with inline encoded payloads or remote content retrieval patterns. It correlates these process executions with recent entries in the Windows RunMRU registry key to identify commands triggered via the Run dialog.