name: Linux Clipboard Data Copy id: 7173b2ad-6146-418f-85ae-c3479e4515fc version: 1 date: '2022-07-28' author: Michael Haag, Splunk status: production type: Anomaly description: The following analytic identifies the use of Linux Xclip copying data out of the clipboard. Adversaries have utilized this technique to capture passwords, IP addresses, or store payloads. data_source: - Sysmon Event ID 1 search: selection1: CommandLine: - '*-o *' - '*-sel *' - '*-selection *' - '*clip *' - '*clipboard*' Image|endswith: xclip condition: selection1 how_to_implement: To successfully implement this search you need to be ingesting information on process that include the name of the process responsible for the changes from your endpoints into the `Endpoint` datamodel in the `Processes` node. In addition, confirm the latest CIM App 4.20 or higher is installed and the latest TA for the endpoint product. known_false_positives: False positives may be present on Linux desktop as it may commonly be used by administrators or end users. Filter as needed. references: - https://attack.mitre.org/techniques/T1115/ - https://linux.die.net/man/1/xclip tags: analytic_story: - Linux Living Off The Land asset_type: Endpoint confidence: 40 impact: 40 message: An instance of $process_name$ was identified on endpoint $dest$ by user $user$ adding or removing content from the clipboard. mitre_attack_id: - T1115 observable: - name: user type: User role: - Victim - name: dest type: Hostname role: - Victim - name: process_name type: Process role: - Child Process product: - Splunk Enterprise - Splunk Enterprise Security - Splunk Cloud risk_score: 16 security_domain: endpoint tests: - name: True Positive Test attack_data: - data: https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1115/atomic_red_team/linux-sysmon.log source: Syslog:Linux-Sysmon/Operational sourcetype: sysmon_linux update_timestamp: true