Data Copied To Clipboard Via Clip.EXE

Last updated on:

About the rule

Rule Type

Standard

Rule Description

Detects the execution of clip.exe in order to copy data to the clipboard. Adversaries may collect data stored in the clipboard from users copying information within or between applications.

Severity

Attention

Rule Requirement

Criteria

Action1: actionname = "Process started" AND PROCESSNAME endswith "\clip.exe" OR ORIGINALFILENAME = "clip.exe" select Action1.HOSTNAME,Action1.MESSAGE,Action1.COMMANDLINE,Action1.FILE_NAME,Action1.PROCESSNAME,Action1.USERNAME,Action1.PARENTPROCESSNAME

Detection

Execution Mode

realtime

Log Sources

Windows

Author

frack113