Possible Clipboard Data Capture via PowerShell (via process_creation)

PremiumReviewedSigma · Low · v1
Product
windows
Category
process_creation
Author
HuntRule
Published
2026-09-04
Updated
2026-09-04

ATT&CK techniques

Collection
  1. Recon

  2. Resource Dev

  3. Initial Access

  4. Execution

  5. Persistence

  6. Priv Esc

  7. Defense Evasion

  8. Cred Access

  9. Discovery

  10. Lateral Movement

  11. C2

  12. Exfiltration

  13. Impact

What it detects

This rule detects PowerShell reading the clipboard through Get-Clipboard or the Forms Clipboard class, a collection technique used to steal copied passwords, tokens or wallet addresses. Clipboard capture is tracked in the Red Canary Threat Detection Report. Detecting these calls surfaces harvesting of sensitive copied data.

Related detections8 linkedT1115 — drag to rearrange
macOS pbpaste Clipboard Read via Process Execution
macOS osascript Clipboard Access via AppleScript Commands
Linux Clipboard Data Collection via xclip -sel clip -o
Linux xclip Clipboard Image Collection via Image MIME Types
Clipboard Data Collection via xclip (auditd Linux EXECVE)
Windows: clip.exe Execution to Copy Data to Clipboard
Windows PowerShell Get-Clipboard Command Execution
PowerShell Get-Clipboard Cmdlet Execution via CLI on Windows
Possible Clipboard Data Capture via PowerShell (via process_creation)
Pivot detection · T1115 · 8 related

Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.