Detection rules › Sigma

Clipboard Collection of Image Data with Xclip Tool

Status
test
Severity
low
Log source
product linux, service auditd
Author
Pawel Mazur
Source
github.com/SigmaHQ/sigma

Detects attempts to collect image data stored in the clipboard from users with the usage of xclip tool. Xclip has to be installed. Highly recommended using rule on servers, due to high usage of clipboard utilities on user workstations.

MITRE ATT&CK coverage

TacticTechniques
CollectionT1115 Clipboard Data

Event coverage

Rule body yaml

title: Clipboard Collection of Image Data with Xclip Tool
id: f200dc3f-b219-425d-a17e-c38467364816
status: test
description: |
  Detects attempts to collect image data stored in the clipboard from users with the usage of xclip tool.
  Xclip has to be installed.
  Highly recommended using rule on servers, due to high usage of clipboard utilities on user workstations.
references:
    - https://linux.die.net/man/1/xclip
author: 'Pawel Mazur'
date: 2021-10-01
modified: 2022-10-09
tags:
    - attack.collection
    - attack.t1115
logsource:
    product: linux
    service: auditd
detection:
    selection:
        type: EXECVE
        a0: xclip
        a1:
            - '-selection'
            - '-sel'
        a2:
            - clipboard
            - clip
        a3: '-t'
        a4|startswith: 'image/'
        a5: '-o'
    condition: selection
falsepositives:
    - Legitimate usage of xclip tools
level: low

Stages and Predicates

Stage 0: condition

selection

Stage 1: selection

selection:
    type: EXECVE
    a0: xclip
    a1:
        - '-selection'
        - '-sel'
    a2:
        - clipboard
        - clip
    a3: '-t'
    a4|startswith: 'image/'
    a5: '-o'

Indicators

Each row is a field, operator, and value that the rule matches. The corpus column counts how many other rules in the catalog look for the same combination: high numbers point to widely-used, community-vetted indicators. Blank or 1 shows that the indicator is specific to this rule.

FieldKindValues
a0eq
  • xclip
a1eq
  • -sel
  • -selection
a2eq
  • clip
  • clipboard
a3eq
  • -t
a4starts_with
  • image/
a5eq
  • -o
typeeq
  • EXECVE