heroui logo

Data Copied To Clipboard Via Clip.EXE

Sigma Rules

View Source
Summary
This detection rule identifies instances of data being copied to the clipboard via the execution of the 'clip.exe' utility on Windows systems. The rule focuses on monitoring for process creation events that involve 'clip.exe', which can be indicative of adversarial behavior when viewing or exfiltrating sensitive information. Attackers may exploit clipboard functionality to gather information that users have copied, which is especially relevant in environments with sensitive data workflows.
Categories
  • Windows
  • Endpoint
Data Sources
  • Process
ATT&CK Techniques
  • T1115
Created: 2021-07-27