Microsoft has released Sysmon 12 and it comes with a useful feature that logs any data added to the Windows Clipboard.
This feature can help system administrators and incident responders monitor the activities of malicious actors that may compromise a system.
For those unfamiliar with Sysmon, otherwise known as System Monitor, it is a Sysinternals tool that monitors Windows systems for malicious activity and logs it to the Windows event log.

With the release of Sysmon 12, users can now configure the utility to generate an event whenever data is copied to the Clipboard. Clipboard data is also saved in files accessible only by administrators for future review.
As most attackers use the Clipboard when copying and pasting Long Commands, monitoring the data stored in the Clipboard can provide useful information about how an attack is being conducted.
To use the feature, download Sysmon 12 from the dedicated Sysinternal or https://live.sysinternals.com/sysmon.exe.
After downloading, run it from a command prompt with elevated privileges, as it needs administrator privileges to run.
Simply running Sysmon.exe will display a “help screen” and for more detailed information, you can go to the Sysmon.
Without any configuration, Sysmon will monitor basic events such as process creation and temporal changes to running files.
If we configure it, it can also record many other types of events, by creating a Sysmon configuration file, which we will do to enable the new "CaptureClipboard" directive.
For a very basic setup that will allow Clipboard connection and recording, you can use the configuration file shown below:

To start Sysmon and direct it to use the above configuration file, you will need to enter the following command from an elevated command prompt :

Once started, Sysmon will install the driver and start collecting data silently in the background.
All Sysmon events will be logged in “Applications and Services Logs/Microsoft/Windows/Sysmon/Operational” in Event Viewer.
With the CaptureClipboard feature enabled, when data is copied to the Clipboard, an “Event 24 – Clipboard Changed” entry will be created in the Event Viewer, as seen below.

The event log entry will show which process saved the data to the clipboard, the user who copied it, and when it was done. However, it will not show the actual data that was copied.
The copied data is stored in the protected folder C:\Sysmon C:\Sysmon in files whose names are of the type clip-SHA1_HASH, where the hash is provided in the above event.
For example, the event shown above will have the Clipboard contents saved to the file C:\Sysmon\CLIP-CC849193D18FF95761CD8A702B66857F329BE85B.
This C:\Sysmon folder is protected with a system ACL and to access it, you need to download the psexec.exe program and start a cmd prompt with system privileges using the following command:

After starting the new system command prompt, you can go to the C:\Sysmon folder to access the saved clipboard data.

When opening the file CLIP-CC849193D18FF95761CD8A702B66857F329BE85B, you can see that it contains a PowerShell command which is copied to Notepad.

This PowerShell command is used to clear Shadow Volume Copies in Windows, which can be used by an attacker who wants to make it more difficult to restore deleted data.
The existence of this information shows how useful this function can be when performing an “incident response”.
Another useful feature added to Microsoft Sysmon 11 will automatically back up deleted files, allowing administrators to recover files that have been used in an attack.
Source: Bleepingcomputer.com
