PowerShell Get-Clipboard Cmdlet Execution via CLI on Windows

Flags Windows command lines containing Get-Clipboard, indicating potential clipboard data collection via PowerShell.

FreeReviewedSigma · Medium · v1
Product
windows
Category
process_creation
Author
Nasreddine Bencherchali (Nextron Systems) (SigmaHQ), DRL 1.1
Published
2020-05-02
Updated
2026-07-30
title: PowerShell Get-Clipboard Cmdlet Execution via CLI on Windows
id: d7405b4d-306e-4ab8-99b2-9228a604e704
related:
  - id: 4cbd4f12-2e22-43e3-882f-bff3247ffb78
    type: derived
  - id: b9aeac14-2ffd-4ad3-b967-1354a4e628c3
    type: derived
status: test
description: This rule identifies process executions where the command line contains the PowerShell Get-Clipboard cmdlet. Adversaries can use clipboard access to collect sensitive information from the system without direct user interaction. The detection relies on Windows process creation telemetry, specifically the command line content of spawned processes.
references:
  - https://github.com/OTRF/detection-hackathon-apt29/issues/16
  - https://github.com/OTRF/ThreatHunter-Playbook/blob/2d4257f630f4c9770f78d0c1df059f891ffc3fec/docs/evals/apt29/detections/3.B.2_C36B49B5-DF58-4A34-9FE9-56189B9DEFEA.md
  - https://github.com/SigmaHQ/sigma/blob/master/rules/windows/process_creation/proc_creation_win_powershell_get_clipboard.yml
author: Nasreddine Bencherchali (Nextron Systems), Huntrule Team
date: 2020-05-02
modified: 2022-12-25
tags:
  - attack.collection
  - attack.t1115
logsource:
  category: process_creation
  product: windows
detection:
  selection:
    CommandLine|contains: Get-Clipboard
  condition: selection
falsepositives:
  - Unknown
level: medium
license: DRL-1.1