ClickFix and Phishing solution:
Local LLM running on the host, melting a GPU all day.
LLM literally just watches what the user does and isn’t a granny.
If the user ends up on a ClickFix page, clicks a phishing link, fake o365 login, etc. it network contains their machine and sends screenshots to the SOC.
It’s invasive, resource intense or costly if cloud, but would probably kill like 90% of the ACTUAL security vulnerabilities in your environment - bad human judgement.