Possible Data Copied To Clipboard Through Clip.EXE (via process_creation)

This rule detects the execution of clip.exe to copy data to the clipboard. Threat actors may collect data stored in the clipboard from users copying information within or between applications.

SigmalowWindowsv1
sigma
title: Possible Data Copied To Clipboard Through Clip.EXE (via process_creation)
id: b3c1874d-4fb0-5d72-838f-1aa6a96ecb74
status: stable
description: This rule detects the execution of clip.exe to copy data to the clipboard. Threat actors may collect data stored in the clipboard from users copying information within or between applications.
references:
    - https://attack.mitre.org/techniques/T1115/
    - https://learn.microsoft.com/en-us/windows-server/administration/windows-commands/clip
    - https://github.com/redcanaryco/atomic-red-team/blob/f339e7da7d05f6057fdfcdd3742bfcf365fee2a9/atomics/T1115/T1115.md
author: Huntrule Team
date: 2026-05-21
tags:
    - attack.collection
    - attack.t1115
logsource:
    category: process_creation
    product: windows
detection:
    selection:
        - Image|endswith: '\clip.exe'
        - OriginalFileName: clip.exe
    condition: selection
falsepositives:
    - Unknown
level: low
regression_tests_path: regression_data/rules/windows/process_creation/proc_creation_win_clip_execution/info.yml
simulation:
    - type: atomic-red-team
      name: Utilize Clipboard to store or execute commands from
      technique: T1115
      atomic_guid: 0cd14633-58d4-4422-9ede-daa2c9474ae7

Known false positives

  • Unknown

Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.