T1115 Splunk · SPL

Detect Clipboard Data in Splunk

Adversaries may collect data stored in the clipboard from users copying information within or between applications. On Windows, adversaries can read clipboard contents using PowerShell's Get-Clipboard cmdlet, the Win32 API functions OpenClipboard() and GetClipboardData(), or by invoking clip.exe in combination with scripting. macOS and Linux provide pbpaste and xclip/xsel utilities respectively. Clipboard content frequently contains high-value data including passwords copied from password managers, authentication tokens, cryptocurrency wallet addresses, PII, and internal URLs. Advanced malware such as Agent Tesla, RTM, Astaroth, CHIMNEYSWEEP, and DarkComet implement persistent clipboard monitoring loops that exfiltrate captured content, while crypto-clippers (a subclass) additionally replace clipboard content with attacker-controlled values to hijack cryptocurrency transactions.

MITRE ATT&CK

Tactic
Collection
Technique
T1115 Clipboard Data
Canonical reference
https://attack.mitre.org/techniques/T1115/

SPL Detection Query

Splunk (SPL)
spl
index=wineventlog sourcetype="XmlWinEventLog:Microsoft-Windows-Sysmon/Operational" EventCode=1
| eval Image=lower(Image)
| eval CommandLine=lower(CommandLine)
| eval ParentImage=lower(ParentImage)
// Branch 1: Scripting engines invoking clipboard APIs
| eval IsScriptEngine=if(match(Image, "(powershell\.exe|pwsh\.exe|python[0-9]*\.exe|wscript\.exe|cscript\.exe|mshta\.exe|perl\.exe|ruby\.exe|node\.exe)"), 1, 0)
| eval ClipboardAPI=if(match(CommandLine, "(get-clipboard|getclipboard|openclipboard|getclipboarddata|win32clipboard|pyperclip|clipboard\.paste|system\.windows\.forms\.clipboard|clipboard::gettext|clipboard\.gettext)"), 1, 0)
// Branch 2: Native clipboard utilities
| eval NativeClipUtil=if(match(Image, "(\\\\clip\.exe$|\\\\xclip$|\\\\xsel$|\\\\xdotool$)"), 1, 0)
| eval SuspiciousParent=if(match(ParentImage, "(winword\.exe|excel\.exe|powerpnt\.exe|outlook\.exe|mshta\.exe|wscript\.exe|cscript\.exe|regsvr32\.exe|rundll32\.exe|msiexec\.exe|python[0-9]*\.exe|perl\.exe|ruby\.exe|node\.exe)"), 1, 0)
// Branch 3: Clipboard monitoring loop pattern
| eval ClipboardLoop=if(match(CommandLine, "get-clipboard") AND match(CommandLine, "(while|start-sleep|foreach|-loop)"), 1, 0)
// Score and filter
| eval ClipboardScore=ClipboardAPI + NativeClipUtil + ClipboardLoop
| eval SuspicionScore=ClipboardScore + (if(IsScriptEngine=1 AND ClipboardAPI=1, 1, 0)) + (if(NativeClipUtil=1 AND SuspiciousParent=1, 1, 0)) + (if(ClipboardLoop=1, 2, 0))
| eval DetectionBranch=case(
    ClipboardLoop=1, "ClipboardMonitoringLoop",
    IsScriptEngine=1 AND ClipboardAPI=1, "ScriptClipboardAccess",
    NativeClipUtil=1 AND SuspiciousParent=1, "ClipboardUtilitySuspiciousParent",
    true(), "Informational")
| where SuspicionScore > 0
| table _time, host, User, Image, CommandLine, ParentImage, ParentCommandLine, DetectionBranch, ClipboardAPI, NativeClipUtil, ClipboardLoop, SuspicionScore
| sort - SuspicionScore, - _time
medium severity medium confidence

Detects clipboard data collection using Sysmon Event ID 1 (Process Creation) logs. Evaluates three detection branches: scripting engines (PowerShell, Python, WScript) invoking clipboard APIs or modules; native clipboard utilities spawned from suspicious parent processes; and persistent clipboard monitoring loops using sleep/while constructs. A cumulative suspicion score aids analyst prioritization. ClipboardLoop receives a higher weight (+2) due to its strong association with RAT-style persistent data harvesting. The DetectionBranch field helps analysts quickly categorize the alert type for appropriate triage playbook selection.

Data Sources

Process: Process CreationCommand: Command ExecutionSysmon Event ID 1

Required Sourcetypes

XmlWinEventLog:Microsoft-Windows-Sysmon/Operational

False Positives & Tuning

  • Password managers (KeePass, Bitwarden, 1Password) auto-clearing clipboard after paste using scripts or scheduled tasks
  • Remote Desktop Protocol (RDP) and virtual desktop infrastructure (VDI) clipboard synchronization agents running as background services
  • Legitimate clipboard manager utilities (Ditto, ClipX, CopyQ, Paste) that monitor and log clipboard history for productivity
  • Accessibility software and screen readers (NVDA, JAWS, Windows Narrator) that access clipboard content for reading aloud
  • Development and testing automation frameworks (Selenium, AutoHotkey, PyAutoGUI) using clipboard for UI automation workflows
  • Help desk and IT tools that read clipboard content for ticketing or remote assistance purposes
Download portable Sigma rule (.yml)

Other platforms for T1115


Testing Methodology

Validate this detection against 5 adversary techniques from Atomic Red Team. Each test below lists the behaviour to exercise and the telemetry you should expect to see. Executable commands and cleanup steps are available with Pro.

  1. Test 1PowerShell Clipboard Harvest via Get-Clipboard

    Expected signal: Sysmon Event ID 1: Process Create with Image=powershell.exe, CommandLine containing 'Get-Clipboard'. Sysmon Event ID 11: File Create for %TEMP%\df00tech-clip-test.txt. PowerShell ScriptBlock Log Event ID 4104 showing the full Get-Clipboard invocation. Security Event ID 4688 if command line auditing is enabled.

  2. Test 2PowerShell Persistent Clipboard Monitoring Loop

    Expected signal: Sysmon Event ID 1: Process Create with CommandLine containing 'Get-Clipboard', 'while', 'Start-Sleep', and '-WindowStyle Hidden'. PowerShell ScriptBlock Log Event ID 4104 showing the full loop. Sysmon Event ID 11: File Create and multiple File Modify events for the staging file. Multiple writes to the staging file visible in DeviceFileEvents.

  3. Test 3Python Clipboard Theft via win32clipboard

    Expected signal: Sysmon Event ID 1: Process Create with Image=python.exe, CommandLine containing 'win32clipboard', 'OpenClipboard', and 'GetClipboardData'. Security Event ID 4688 if command line auditing is enabled. Note: requires pywin32 package installed (pip install pywin32).

  4. Test 4Linux Clipboard Exfiltration via xclip

    Expected signal: Auditd syscall log with EXECVE for xclip with arguments '-selection clipboard -o'. Syslog process creation event for xclip. File creation event for /tmp/df00tech-clipboard-capture.txt. If Sysmon for Linux is deployed: EventCode=1 with Image=/usr/bin/xclip.

  5. Test 5macOS Clipboard Collection via pbpaste

    Expected signal: macOS Unified Log (ULS): process creation for pbpaste with arguments. File creation for /tmp/df00tech-clipboard-macos.txt. If Jamf or similar MDM telemetry is deployed, process execution event with parent shell context. ESF (Endpoint Security Framework) events if EDR is deployed.

Unlock Pro Content

Get the full detection package for T1115 including response playbook, investigation guide, and atomic red team tests.

Response PlaybookInvestigation GuideHunting QueriesAtomic Red Team TestsTuning Guidance

Related Detections