Elastic medium stable eql

Suspicious pbpaste High Volume Activity

Identifies a high volume of `pbpaste` executions, which may indicate a bash loop continuously collecting clipboard contents, potentially allowing an attacker to harvest user credentials or other sensitive information.

View Source

Detection Logic

sequence by host.hostname, host.id with maxspan=1m
[process where host.os.type == "macos" and event.type == "start" and event.action == "exec" and process.name: "pbpaste"] with runs = 5

Field Validations

Loading…

Comments (0)

Loading comments...