Possible Data Copied To Clipboard Through Clip.EXE (via process_creation)
This rule detects the execution of clip.exe to copy data to the clipboard. Threat actors may collect data stored in the clipboard from users copying information within or between applications.
SigmalowWindowsv1
sigma
possible-data-copied-to-clipboard-through-clip-exe-via-process-creation
title: Possible Data Copied To Clipboard Through Clip.EXE (via process_creation)
id: b3c1874d-4fb0-5d72-838f-1aa6a96ecb74
status: stable
description: This rule detects the execution of clip.exe to copy data to the clipboard. Threat actors may collect data stored in the clipboard from users copying information within or between applications.
references:
- https://attack.mitre.org/techniques/T1115/
- https://learn.microsoft.com/en-us/windows-server/administration/windows-commands/clip
- https://github.com/redcanaryco/atomic-red-team/blob/f339e7da7d05f6057fdfcdd3742bfcf365fee2a9/atomics/T1115/T1115.md
author: Huntrule Team
date: 2026-05-21
tags:
- attack.collection
- attack.t1115
logsource:
category: process_creation
product: windows
detection:
selection:
- Image|endswith: '\clip.exe'
- OriginalFileName: clip.exe
condition: selection
falsepositives:
- Unknown
level: low
regression_tests_path: regression_data/rules/windows/process_creation/proc_creation_win_clip_execution/info.yml
simulation:
- type: atomic-red-team
name: Utilize Clipboard to store or execute commands from
technique: T1115
atomic_guid: 0cd14633-58d4-4422-9ede-daa2c9474ae7
Known false positives
- Unknown
Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.