elastic
medium
eql
Suspicious pbpaste High Volume Activity
Identifies a high volume of `pbpaste` executions, which may indicate a bash loop continuously collecting clipboard
contents, potentially allowing an attacker to harvest user credentials or other sensitive information.