1200KM / detection
T1115 Clipboard Data — Detection Rules
Detection workspace for T1115 Clipboard Data: 7 Sigma sources, 0 Atlas concepts and 0 anomaly models. No live detection validation.
Source-backed rule directory
- Clipboard Collection with Xclip Tool - Auditd · test · low · {"product":"linux","service":"auditd"}
- Clipboard Collection of Image Data with Xclip Tool · test · low · {"product":"linux","service":"auditd"}
- Clipboard Collection with Xclip Tool · test · low · {"product":"linux","category":"process_creation"}
- Clipboard Access Via OSAScript · test · medium · {"product":"macos","category":"process_creation"}
- PowerShell Get Clipboard · test · medium · {"product":"windows","category":"ps_module","definition":"0ad03ef1-f21b-4a79-8ce8-e6900c54b65b"}
- Data Copied To Clipboard Via Clip.EXE · test · low · {"category":"process_creation","product":"windows"}
- PowerShell Get-Clipboard Cmdlet Via CLI · test · medium · {"category":"process_creation","product":"windows"}
Atlas deterministic concepts
No exact concept selected.
Anomaly models
No exact Atlas model in this snapshot.
ATT&CK analytic guidance
DET0341 Clipboard Data Access with Anomalous Context
AN0965 Analytic 0965
Detection of clipboard access via OS utilities (e.g., clip.exe, Get-Clipboard) by non-interactive or abnormal parent processes, potentially chained with staging or exfiltration commands.
AN0966 Analytic 0966
Detection of pbpaste/pbcopy clipboard access by processes without terminal sessions or linked to launch agents, potentially staged for collection.
AN0967 Analytic 0967
Detection of xclip or xsel access to clipboard buffers outside of user terminal context, especially when chained to staging (gzip, base64) or network exfiltration (curl, scp).
Connected ecosystem references
Linked tags
Simulation, tools and telemetry
Threat actor context
These are explicit actor-to-technique associations in the existing Threat Matrix snapshot, not attribution of an event or proof that a detector identifies the actor. No tool-to-actor relationship is inferred.
Existing anomaly research
Pinned research references. No browser attack runner, live simulation result or validated detector is asserted. Source mappings and validation limits are preserved. ATT&CK / Atomic provenance · Detection provenance.