Clipboard Data Collection via xclip (auditd Linux EXECVE)

Alerts on xclip command lines that request clipboard/clip selection output (-o) on Linux systems monitored by auditd.

FreeReviewedSigma · Low · v3
Product
linux
Service
auditd
Author
Pawel Mazur (SigmaHQ), DRL 1.1
Published
2021-09-24
Updated
2026-07-31

ATT&CK techniques

Collection
  1. Recon

  2. Resource Dev

  3. Initial Access

  4. Execution

  5. Persistence

  6. Priv Esc

  7. Defense Evasion

  8. Cred Access

  9. Discovery

  10. Lateral Movement

  11. C2

  12. Exfiltration

  13. Impact

What it detects

This rule flags execution of the xclip utility with arguments targeting clipboard or primary selection output (e.g., -selection/-sel with clipboard/clip) and using the -o option. Attackers may use xclip to quickly collect or exfiltrate user-accessible clipboard contents. It relies on auditd telemetry capturing process execution events (EXECVE) and the specific command-line arguments passed to xclip.

Related detections9 linkedT1115 — drag to rearrange
Suspicious Clipboard Data Access via Get-Clipboard (BeaverTail OtterCookie)
Possible Clipboard Data Capture via PowerShell (via process_creation)
macOS pbpaste Clipboard Read via Process Execution
macOS osascript Clipboard Access via AppleScript Commands
Linux Clipboard Data Collection via xclip -sel clip -o
Linux xclip Clipboard Image Collection via Image MIME Types
Windows: clip.exe Execution to Copy Data to Clipboard
Windows PowerShell Get-Clipboard Command Execution
PowerShell Get-Clipboard Cmdlet Execution via CLI on Windows
Clipboard Data Collection via xclip (auditd Linux EXECVE)
Pivot detection · T1115 · 9 related

Changelog

v3
  1. v3
    Candidate ingested via manual entry.2026-07-31
  2. v2
    Candidate ingested via manual entry.2026-07-31
  3. v1
    No changelog recorded for this version.2026-07-30

Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.