Sysmon Event ID 24: Clipboard content changed
- Event ID
- 24
- Channel
- Microsoft-Windows-Sysmon/Operational
- Provider
- Microsoft-Windows-Sysmon
- Log file
- Microsoft-Windows-Sysmon%4Operational.evtx
- Category
- System
- Default logging
- Needs configuration
What event 24 means
Sysmon event 24 fires when the system clipboard content changes. It logs the process that set the clipboard, the session and hashes of the content; when archiving is enabled, the text is saved to the Sysmon archive directory.
Its main forensic use is RDP: when content is pasted through an RDP session, the setting process is rdpclip.exe and ClientInfo identifies the remote user and client host. That helps prove what an operator copied into or out of a server. Because clipboard data can contain passwords and other secrets, enable archiving with care.
When it is logged
Sysmon 12.0 or later with a <ClipboardChange> rule and the CaptureClipboard configuration entry. Captured contents are stored in ArchiveDirectory.
Key fields
| Field | What it tells you |
|---|---|
| ProcessGuid | Process that changed the clipboard. |
| Image | Executable that changed the clipboard; rdpclip.exe for RDP clipboard redirection. |
| Session | Session ID where the change happened; non-zero sessions are interactive or RDP sessions. |
| ClientInfo | For remote sessions, the remote user and client host name. |
| Hashes | Hashes of the clipboard content; the archived copy is named after them. |
| Archived | true when the content was saved to the archive directory. |
| User | Account of the process. |
Common benign sources
- Every copy action by users — very frequent on workstations.
- Administrators copying commands and paths into RDP sessions.
What attackers do that produces it
- Operators pasting scripts or commands into an RDP session on a compromised server.
- Malware monitoring or replacing clipboard contents (for example swapping cryptocurrency addresses).
Investigation tips
- Filter on Image
rdpclip.exeand read ClientInfo to identify the remote user and host. - Retrieve archived content by hash to see what was pasted, then match with process events right after.
- Correlate with RDP logon events (Security 4624 type 10, RDP 21/25) for the same session.
MITRE ATT&CK techniques
MITRE ATT&CK v19.2. Technique and tactic names are MITRE's.
Sigma rules for this event
No bundled SigmaHQ rule targets this event ID specifically. Rules on related events may still cover the activity.
Run these rules on your logs
Drop a .evtx file into the viewer: all 2,395 bundled SigmaHQ rules run locally in your browser. Nothing is uploaded.