Windows PowerShell Get-Clipboard Command Execution

Flags PowerShell activity that includes the Get-Clipboard command, which may be used to collect clipboard contents.

FreeReviewedSigma · Medium · v2
Product
windows
Category
ps_module
Author
Roberto Rodriguez (Cyb3rWard0g), OTR (Open Threat Research) (SigmaHQ), DRL 1.1
Published
2020-05-02
Updated
2026-07-31

ATT&CK techniques

Collection
  1. Recon

  2. Resource Dev

  3. Initial Access

  4. Execution

  5. Persistence

  6. Priv Esc

  7. Defense Evasion

  8. Cred Access

  9. Discovery

  10. Lateral Movement

  11. C2

  12. Exfiltration

  13. Impact

What it detects

This rule matches PowerShell module logging events whose script content contains the Get-Clipboard command. Access to clipboard contents can enable attackers to capture sensitive data copied by a user. The detection relies on PowerShell telemetry that records module/script payload text and identifies the presence of Get-Clipboard.

Related detections9 linkedT1115 — drag to rearrange
Suspicious Clipboard Data Access via Get-Clipboard (BeaverTail OtterCookie)
Possible Clipboard Data Capture via PowerShell (via process_creation)
macOS pbpaste Clipboard Read via Process Execution
macOS osascript Clipboard Access via AppleScript Commands
Linux Clipboard Data Collection via xclip -sel clip -o
Linux xclip Clipboard Image Collection via Image MIME Types
Clipboard Data Collection via xclip (auditd Linux EXECVE)
Windows: clip.exe Execution to Copy Data to Clipboard
PowerShell Get-Clipboard Cmdlet Execution via CLI on Windows
Windows PowerShell Get-Clipboard Command Execution
Pivot detection · T1115 · 9 related

Changelog

v2
  1. v2
    Candidate ingested via manual entry.2026-07-31
  2. v1
    No changelog recorded for this version.2026-07-30

Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.