Replying to
@cR0w@infosec.exchange I do not but I'm sure you might be aware of these - uBlock Origin has recently started to throw alerts with copied PowerShell to alert users of a potential ClickFix payload, if that's an approved extension rolled out to workstations.
Another mitigation is disabling Win + R (and also Win + X) keybinds specifically. From knowledge, most ClickFix seen is still asking for users to press the keybind rather than open PS explicitly. This is at least an easier mitigation to get backing for rather than fully disabling PS/cmd.
Edit: I just re-read the post sorry, obviously you already knew that. If I can find a resource I'll let you know.
