Technique with 4 sub-techniques.View on attack.mitre.org
Adversaries may use methods of capturing user input to obtain credentials or collect information. During normal system usage, users often provide credentials to various different locations, such as login pages/portals or system dialog boxes. Input capture mechanisms may be transparent to the user (e.g. Credential API Hooking) or rely on deceiving the user into providing input into what they believe to be a genuine service (e.g. Web Portal Capture).
Rules on DetectionCode tagged with T1056 or one of its sub-techniques.
| Rule | Level | Log source | Technique |
|---|---|---|---|
| Linux Keylogging with Pam.d | high | linux / NULL | T1056.001 |
| CredUI.DLL Loaded By Uncommon Process | medium | windows / image_load | T1056.002 |
| Potential Keylogger Activity | medium | windows / ps_script | T1056.001 |
| Powershell Keylogging | medium | windows / ps_script | T1056.001 |
| PUA - Mouse Lock Execution | medium | windows / process_creation | T1056.002 |
| DNS Query Request To OneLaunch Update Service | low | windows / dns_query | T1056 |
| GUI Input Capture - macOS | low | macos / process_creation | T1056.002 |
| Suspicious Network Communication With IPFS | low | NULL / proxy | T1056 |
| Rule | Type | Risk | Data source | Technique |
|---|---|---|---|---|
| MacOS Osascript Displaying Suspicious User Prompt | Anomaly | NULL | Osquery Results | T1056.002 |
| Windows Input Capture Using Credential UI Dll | Hunting | NULL | Sysmon EventID 7 | T1056.002 |
| Used by | Procedure example |
|---|---|
| GroupAPT39 | APT39 has utilized tools to capture mouse movements. |
| GroupAPT42 | APT42 has used credential harvesting websites. |
| GroupStorm-1811 | Storm-1811 has used a PowerShell script to capture user credentials after prompting a user to authenticate to run a malicious script masquerading as a legitimate update item. |
| Used by | Procedure example |
|---|---|
| MalwareChaes | Chaes has a module to perform any API hooking it desires. |
| MalwareFlawedAmmyy | FlawedAmmyy can collect mouse events. |
| MalwareInvisibleFerret | InvisibleFerret has collected mouse and keyboard events using “pyWinhook”. |
| MalwareKobalos | Kobalos has used a compromised SSH client to capture the hostname, port, username and password used to establish an SSH connection from the compromised host. |
| MalwareMafalda | Mafalda can conduct mouse event logging. |
| MalwaremetaMain | metaMain can log mouse events. |
| ToolNPPSPY | NPPSPY captures user input into the Winlogon process by redirecting RPC traffic from legitimate listening DLLs within the operating system to a newly registered malicious item that allows for recording logon information in cleartext. |
| Used by | Procedure example |
|---|---|
| CampaignLeviathan Australian Intrusions | Leviathan captured submitted multfactor authentication codes and other technical artifacts related to remote access sessions during Leviathan Australian Intrusions. |
| CampaignVersa Director Zero Day Exploitation | Versa Director Zero Day Exploitation intercepted and harvested credentials from user logins to compromised devices. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.