Real-world descriptions of how a group, tool or campaign used a technique.
11362 examples
| Technique | Used by | Procedure example |
|---|---|---|
| T1056.001 Keylogging |
MalwarenjRAT | njRAT is capable of logging keystrokes. |
| T1056.001 Keylogging |
MalwareJPIN | JPIN contains a custom keylogger. |
| T1056.001 Keylogging |
MalwaremetaMain | metaMain has the ability to log keyboard events. |
| T1056.001 Keylogging |
MalwareHTTPBrowser | HTTPBrowser is capable of capturing keystrokes on victims. |
| T1056.001 Keylogging |
MalwareAgent Tesla | Agent Tesla can log keystrokes on the victim’s machine. |
| T1056.001 Keylogging |
MalwareECCENTRICBANDWAGON | ECCENTRICBANDWAGON can capture and store keystrokes. |
| T1056.001 Keylogging |
MalwareBADNEWS | When it first starts, BADNEWS spawns a new thread to log keystrokes. |
| T1056.001 Keylogging |
MalwareDRYHOOK | DRYHOOK has captured user credentials and passwords in plaintext and has encrypted them in a stored file on the network device. |
| T1056.001 Keylogging |
MalwareRemexi | Remexi gathers and exfiltrates keystrokes from the machine. |
| T1056.001 Keylogging |
MalwareAstaroth | Astaroth logs keystrokes from the victim's machine. |
| T1056.001 Keylogging |
MalwareQakBot | QakBot can capture keystrokes on a compromised host. |
| T1056.001 Keylogging |
MalwarejRAT | jRAT has the capability to log keystrokes from the victim’s machine, both offline and online. |
| T1056.001 Keylogging |
MalwareHelminth | The executable version of Helminth has a module to log keystrokes. |
| T1056.001 Keylogging |
MalwareMacSpy | MacSpy captures keystrokes. |
| T1056.001 Keylogging |
MalwareDtrack | Dtrack’s dropper contains a keylogging executable. |
| T1056.001 Keylogging |
MalwareADVSTORESHELL | ADVSTORESHELL can perform keylogging. |
| T1056.001 Keylogging |
MalwareWarzoneRAT | WarzoneRAT has the capability to install a live and offline keylogger, including through the use of the `GetAsyncKeyState` Windows API. |
| T1056.001 Keylogging |
MalwareSLOTHFULMEDIA | SLOTHFULMEDIA has a keylogging capability. |
| T1056.001 Keylogging |
ToolSILENTTRINITY | SILENTTRINITY has a keylogging capability. |
| T1056.001 Keylogging |
ToolPowerSploit | PowerSploit's |
| T1056.001 Keylogging |
ToolDCRAT | DCRAT can log keystrokes on targeted systems. |
| T1056.001 Keylogging |
ToolEmpire | Empire includes keylogging capabilities for Windows, Linux, and macOS systems. |
| T1056.001 Keylogging |
ToolPcShare | PcShare has the ability to capture keystrokes. |
| T1056.001 Keylogging |
ToolPoshC2 | PoshC2 has modules for keystroke logging and capturing credentials from spoofed Outlook authentication messages. |
| T1056.001 Keylogging |
ToolAsyncRAT | AsyncRAT can capture keystrokes on the victim’s machine. |
| T1056.001 Keylogging |
ToolRemcos | Remcos has a command for keylogging. |
| T1056.001 Keylogging |
ToolImminent Monitor | Imminent Monitor has a keylogging module. |
| T1056.001 Keylogging |
ToolPupy | Pupy uses a keylogger to capture keystrokes it then sends back to the server after it is stopped. |
| T1056.001 Keylogging |
ToolQuasarRAT | QuasarRAT has a built-in keylogger. |
| T1056.001 Keylogging |
MalwareDuqu | Duqu can track key presses with a keylogger module. |
| T1056.002 GUI Input Capture |
MalwareiKitten | iKitten prompts the user for their credentials. |
| T1056.002 GUI Input Capture |
MalwareCuckoo Stealer | Cuckoo Stealer has captured passwords by prompting victims with a “macOS needs to access System Settings” GUI window. |
| T1056.002 GUI Input Capture |
MalwareKeydnap | Keydnap prompts the users for credentials. |
| T1056.002 GUI Input Capture |
MalwareMispadu | Mispadu can monitor browser activity for online banking actions and display full-screen overlay images to block user access to the intended site or present additional data fields. |
| T1056.002 GUI Input Capture |
MalwareMuddyViper | MuddyViper has displayed a fake Windows Security dialog to gather credentials. |
| T1056.002 GUI Input Capture |
MalwareBundlore | Bundlore prompts the user for their credentials. |
| T1056.002 GUI Input Capture |
MalwareLP-Notes | LP-Notes has displayed a fake Windows Security dialog box to prompt for Windows credentials. |
| T1056.002 GUI Input Capture |
MalwareMetamorfo | Metamorfo has displayed fake forms on top of banking sites to intercept credentials from victims. |
| T1056.002 GUI Input Capture |
MalwareCalisto | Calisto presents an input prompt asking for the user's login and password. |
| T1056.002 GUI Input Capture |
MalwareProton | Proton prompts users for their credentials. |
| T1056.002 GUI Input Capture |
MalwareXCSSET | XCSSET prompts the user to input credentials using a native macOS dialog box leveraging the system process |
| T1056.002 GUI Input Capture |
MalwareDok | Dok prompts the user for credentials. |
| T1056.002 GUI Input Capture |
ToolSILENTTRINITY | SILENTTRINITY's `credphisher.py` module can prompt a current user for their credentials. |
| T1056.003 Web Portal Capture |
MalwareWARPWIRE | WARPWIRE can capture credentials submitted during the web logon process in order to access layer seven applications such as RDP. |
| T1056.003 Web Portal Capture |
MalwareIceApple | The IceApple OWA credential logger can monitor for OWA authentication requests and log the credentials. |
| T1056.004 Credential API Hooking |
MalwareTrickBot | TrickBot has the ability to capture RDP credentials by capturing the |
| T1056.004 Credential API Hooking |
MalwareRDFSNIFFER | RDFSNIFFER hooks several Win32 API functions to hijack elements of the remote system management user-interface. |
| T1056.004 Credential API Hooking |
MalwareNOKKI | NOKKI uses the Windows call SetWindowsHookEx and begins injecting it into every GUI process running on the victim's machine. |
| T1056.004 Credential API Hooking |
MalwareVersaMem | VersaMem hooked and overrided Versa's built-in authentication method, `setUserPassword`, to intercept plaintext credentials when submitted to the server. |
| T1056.004 Credential API Hooking |
MalwareUrsnif | Ursnif has hooked APIs to perform a wide variety of information theft, such as monitoring traffic from browsers. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.