PowerShell Get-Clipboard Cmdlet Execution via CLI on Windows
Flags Windows command lines containing Get-Clipboard, indicating potential clipboard data collection via PowerShell.
- Product
- windows
- Category
- process_creation
- Author
- Nasreddine Bencherchali (Nextron Systems) (SigmaHQ), DRL 1.1
- Published
- 2020-05-02
- Updated
- 2026-07-30
ATT&CK techniques
CollectionRecon
Resource Dev
Initial Access
Execution
Persistence
Priv Esc
Defense Evasion
Cred Access
Discovery
Lateral Movement
Collection
C2
Exfiltration
Impact
What it detects
This rule identifies process executions where the command line contains the PowerShell Get-Clipboard cmdlet. Adversaries can use clipboard access to collect sensitive information from the system without direct user interaction. The detection relies on Windows process creation telemetry, specifically the command line content of spawned processes.
Reporting behind it
- github.comhttps://github.com/OTRF/detection-hackathon-apt29/issues/16
- github.comhttps://github.com/OTRF/ThreatHunter-Playbook/blob/2d4257f630f4c9770f78d0c1df059f891ffc3fec/docs/evals/apt29/detections/3.B.2_C36B49B5-DF58-4A34-9FE9-56189B9DEFEA.md
- github.comhttps://github.com/SigmaHQ/sigma/blob/master/rules/windows/process_creation/proc_creation_win_powershell_get_clipboard.yml
Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.
title: PowerShell Get-Clipboard Cmdlet Execution via CLI on Windows
id: d7405b4d-306e-4ab8-99b2-9228a604e704
related:
- id: 4cbd4f12-2e22-43e3-882f-bff3247ffb78
type: derived
- id: b9aeac14-2ffd-4ad3-b967-1354a4e628c3
type: derived
status: test
description: This rule identifies process executions where the command line contains the PowerShell Get-Clipboard cmdlet. Adversaries can use clipboard access to collect sensitive information from the system without direct user interaction. The detection relies on Windows process creation telemetry, specifically the command line content of spawned processes.
references:
- https://github.com/OTRF/detection-hackathon-apt29/issues/16
- https://github.com/OTRF/ThreatHunter-Playbook/blob/2d4257f630f4c9770f78d0c1df059f891ffc3fec/docs/evals/apt29/detections/3.B.2_C36B49B5-DF58-4A34-9FE9-56189B9DEFEA.md
- https://github.com/SigmaHQ/sigma/blob/master/rules/windows/process_creation/proc_creation_win_powershell_get_clipboard.yml
author: Nasreddine Bencherchali (Nextron Systems), Huntrule Team
date: 2020-05-02
modified: 2022-12-25
tags:
- attack.collection
- attack.t1115
logsource:
category: process_creation
product: windows
detection:
selection:
CommandLine|contains: Get-Clipboard
condition: selection
falsepositives:
- Unknown
level: medium
license: DRL-1.1