@BleepingComputer Just an idea: when testing the protection, copy the malicious command from a web page, like in a real attack scenario - and not, say, from a text file. At least on Windows, this matters.Here's similar protection for Windows but, unfortunately, it needs to run as Administrator:https://github.com/CertainlyP/ClipGuard