Clipboard Data Theft via OpenClipboard/GetClipboardData (T1115)

This rule detects potential clipboard data theft by monitoring Windows Sysmon Event ID 10 for process access events involving clipboard-related APIs (OpenClipboard, GetClipboardData) by untrusted processes, and PowerShell Script Block Logging (Event ID 4104) for the use of Get-Clipboard cmdlets. This identifies attempts by non-standard or unauthorized processes to access sensitive information copied by a user.