Skip to content
Sysmon

Sysmon Event ID 24: Clipboard content changed

ClipboardChange (New content in the clipboard)Sysmon event 24 records a change to clipboard contents, with process, session and hash; contents can be archived. Useful for RDP copy-paste investigations.
24
Event ID
24
Channel
Microsoft-Windows-Sysmon/Operational
Provider
Microsoft-Windows-Sysmon
Log file
Microsoft-Windows-Sysmon%4Operational.evtx
Category
System
Default logging
Needs configuration

What event 24 means

Sysmon event 24 fires when the system clipboard content changes. It logs the process that set the clipboard, the session and hashes of the content; when archiving is enabled, the text is saved to the Sysmon archive directory.

Its main forensic use is RDP: when content is pasted through an RDP session, the setting process is rdpclip.exe and ClientInfo identifies the remote user and client host. That helps prove what an operator copied into or out of a server. Because clipboard data can contain passwords and other secrets, enable archiving with care.

When it is logged

Audit policy / configuration

Sysmon 12.0 or later with a <ClipboardChange> rule and the CaptureClipboard configuration entry. Captured contents are stored in ArchiveDirectory.

Key fields

FieldWhat it tells you
ProcessGuidProcess that changed the clipboard.
ImageExecutable that changed the clipboard; rdpclip.exe for RDP clipboard redirection.
SessionSession ID where the change happened; non-zero sessions are interactive or RDP sessions.
ClientInfoFor remote sessions, the remote user and client host name.
HashesHashes of the clipboard content; the archived copy is named after them.
Archivedtrue when the content was saved to the archive directory.
UserAccount of the process.

Common benign sources

  • Every copy action by users — very frequent on workstations.
  • Administrators copying commands and paths into RDP sessions.

What attackers do that produces it

  • Operators pasting scripts or commands into an RDP session on a compromised server.
  • Malware monitoring or replacing clipboard contents (for example swapping cryptocurrency addresses).

Investigation tips

  • Filter on Image rdpclip.exe and read ClientInfo to identify the remote user and host.
  • Retrieve archived content by hash to see what was pasted, then match with process events right after.
  • Correlate with RDP logon events (Security 4624 type 10, RDP 21/25) for the same session.

MITRE ATT&CK techniques

TechniqueTactics
T1115 Clipboard DataCollection
T1021.001 Remote Services: Remote Desktop ProtocolLateral Movement

MITRE ATT&CK v19.2. Technique and tactic names are MITRE's.

Sigma rules for this event

No bundled SigmaHQ rule targets this event ID specifically. Rules on related events may still cover the activity.

Run these rules on your logs

Drop a .evtx file into the viewer: all 2,395 bundled SigmaHQ rules run locally in your browser. Nothing is uploaded.

Sources and further reading