2026 Critical Enterprise Intrusion Chain Detection: ClickFix-Style Fake CAPTCHA Initial Access via mshta/wscript/powershell
Detects the ClickFix/fake-CAPTCHA initial access pattern where users are socially engineered into copying and pasting malicious commands into the Windows Run dialog or a browser-spawned shell. The rule matches on process creation events involving mshta.exe, powershell.exe, or wscript.exe initiated by explorer.exe or common shell-related processes, filtering out known administrative and deployment software.
SentinelOne

