name: Linux Clipboard Data Copy id: 7173b2ad-6146-418f-85ae-c3479e4515fc version: 1 date: '2022-07-28' author: Michael Haag, Splunk type: Anomaly datamodel: - Endpoint description: The following analytic identifies the use of Linux Xclip copying data out of the clipboard. Adversaries have utilized this technique to capture passwords, IP addresses, or store payloads. search: '| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time) as lastTime from datamodel=Endpoint.Processes where Processes.process_name=xclip Processes.process IN ("*-o *", "*-sel *", "*-selection *", "*clip *","*clipboard*") by Processes.dest Processes.user Processes.parent_process_name Processes.process_name Processes.process Processes.process_id Processes.parent_process_id | `drop_dm_object_name(Processes)` | `security_content_ctime(firstTime)` | `security_content_ctime(lastTime)` | `linux_clipboard_data_copy_filter`' how_to_implement: To successfully implement this search you need to be ingesting information on process that include the name of the process responsible for the changes from your endpoints into the `Endpoint` datamodel in the `Processes` node. In addition, confirm the latest CIM App 4.20 or higher is installed and the latest TA for the endpoint product. known_false_positives: False positives may be present on Linux desktop as it may commonly be used by administrators or end users. Filter as needed. references: - https://attack.mitre.org/techniques/T1115/ - https://linux.die.net/man/1/xclip tags: analytic_story: - Linux Living Off The Land asset_type: Endpoint cis20: - CIS 3 - CIS 5 - CIS 16 confidence: 40 context: - Source:Endpoint - Stage:Discovery dataset: - https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1115/atomic_red_team/linux-sysmon.log impact: 40 kill_chain_phases: - Reconnaissance message: An instance of $process_name$ was identified on endpoint $dest$ by user $user$ adding or removing content from the clipboard. mitre_attack_id: - T1115 nist: - DE.CM observable: - name: user type: User role: - Victim - name: dest type: Hostname role: - Victim - name: process_name type: Process role: - Child Process product: - Splunk Enterprise - Splunk Enterprise Security - Splunk Cloud required_fields: - _time - Processes.dest - Processes.user - Processes.parent_process_name #parent process name - Processes.parent_process #parent cmdline - Processes.original_file_name - Processes.process_name #process name - Processes.process #process cmdline - Processes.process_id - Processes.parent_process_path - Processes.process_path - Processes.parent_process_id risk_score: 16 security_domain: endpoint