# Clipboard Armor: spot an app that goes online right after you copy something

> Clipboard Armor flags an app’s first-ever connection when it happens seconds after your clipboard changes, a timing pattern clipboard stealers rely on, without ever reading what you copied.

FireAI Docs (HisnLabs) · Recurso · Disponível desde o FireAI 0.1.6
Canonical: https://hisnlabs.com/fireai/en/docs/clipboard-armor

**Onde no FireAI:** World map › Clipboard

Copy passwords, wallet addresses and codes with one more pair of eyes on what happens next.

You copy things you’d never type into a website: passwords, one-time codes, bank details, crypto wallet addresses. Some harmful apps wait for exactly that moment, grab what you copied, and send it out. Clipboard Armor watches for the tell-tale timing.

## How it works

- FireAI notices that your clipboard changed. It never reads what’s in it; macOS only tells it “something changed”, and that’s all it keeps: the time.
- If an app then makes its very first connection to a new destination within about three seconds, FireAI adds that coincidence to the connection’s risk facts in [Investigate](https://hisnlabs.com/fireai/en/docs/investigate-a-connection).
- The Clipboard button on the World map lists any connection flagged this way. An empty list is the normal, good case.

> **Note:** It’s one fact among others, never a verdict on its own. A connection is only called risky when several signals line up, such as a destination on a threat list or an unsigned app.

## Honest limits

- macOS has no way for any app to see which other app read the clipboard. FireAI works from timing, not proof.
- Innocent tools can match the pattern too: a password manager filling a form, or a sync app sending your copied text to your phone.
- It looks at an app’s first connection to a place, so an app that already talks to the same server every day won’t be flagged by this alone.

If a flagged app shouldn’t be online at all, [block it in one click](https://hisnlabs.com/fireai/en/docs/block-an-app-or-a-company). For apps launched from a USB stick, see [USB Network Protection](https://hisnlabs.com/fireai/en/docs/usb-network-protection).

## Leia em seguida

- [Investigate a connection](https://hisnlabs.com/fireai/pt-br/docs/investigate-a-connection.md)
- [The Threats page: what looks wrong, and why](https://hisnlabs.com/fireai/pt-br/docs/the-threats-page.md)
- [USB Network Protection: nothing from a USB drive goes online unasked](https://hisnlabs.com/fireai/pt-br/docs/usb-network-protection.md)
- [Block an app’s internet access on Mac, or just one company or domain](https://hisnlabs.com/fireai/pt-br/docs/block-an-app-or-a-company.md)

---

Teste todos os recursos grátis por 17 dias, sem cartão. Garantia de reembolso de 30 dias. [Baixar para Mac](https://hisnlabs.com/fireai/pt-br/download)
