Ran into a ClickFix incident where the commands were obfuscated like: "c^u^rl.e^x^e

Probably worth flagging on Commands that contain excessive carrots and have a parent process of explorer.exe or conhost.exe

#clickfix #intel #cybersecurity #blueteam #incidentresponse

@bon3s excessive carrots detected 🥕🥕. Deploying defences...🐇 ;)

*I'm guessing you got auto'corrected' from ^Carets^

@ketumbra I'm owning it now 🥕