Technique.View on attack.mitre.org
Adversaries may attempt to take screen captures of the desktop to gather information over the course of an operation. Screen capturing functionality may be included as a feature of a remote access tool used in post-compromise operations. Taking a screenshot is also typically possible through native utilities or API calls, such as CopyFromScreen, xwd, or screencapture.
Rules on DetectionCode tagged with T1113.
| Rule | Level | Log source |
|---|---|---|
| Periodic Backup For System Registry Hives Enabled | medium | windows / registry_set |
| Screen Capture Activity Via Psr.EXE | medium | windows / process_creation |
| Windows Recall Feature Enabled - DisableAIDataAnalysis Value Deleted | medium | windows / registry_delete |
| Windows Recall Feature Enabled - Registry | medium | windows / registry_set |
| Windows Recall Feature Enabled Via Reg.EXE | medium | windows / process_creation |
| Windows Screen Capture with CopyFromScreen | medium | windows / ps_script |
| Screen Capture - macOS | low | macos / process_creation |
| Screen Capture with Import Tool | low | linux / NULL |
| Screen Capture with Xwd | low | linux / NULL |
| Rule | Type | Risk | Data source |
|---|---|---|---|
| Remcos RAT File Creation in Remcos Folder | TTP | NULL | Sysmon EventID 11 |
| Suspicious Image Creation In Appdata Folder | TTP | NULL | Sysmon EventID 1 AND Sysmon EventID 11 |
| Suspicious WAV file in Appdata Folder | TTP | NULL | Sysmon EventID 1 AND Sysmon EventID 11, Windows Event Log Security 4688 AND Sysmon EventID 11 |
| Windows Screen Capture in TEMP folder | TTP | NULL | Sysmon EventID 11 |
| Windows Screen Capture Via Powershell | TTP | NULL | Powershell Script Block Logging 4104 |
| Used by | Procedure example |
|---|---|
| GroupAPT28 | APT28 has used tools to take screenshots from victims. |
| GroupAPT39 | APT39 has used a screen capture utility to take screenshots on a compromised host. |
| GroupAPT42 | APT42 has used malware, such as GHAMBAR and POWERPOST, to take screenshots. |
| GroupBRONZE BUTLER | BRONZE BUTLER has used a tool to capture screenshots. |
| GroupDark Caracal | Dark Caracal took screenshots using their Windows malware. |
| GroupDragonfly | Dragonfly has performed screen captures of victims, including by using a tool, scr.exe (which matched the hash of ScreenUtil). |
| GroupFIN7 | FIN7 captured screenshots and desktop video recordings. |
| GroupGamaredon Group | Gamaredon Group's malware can take screenshots of the compromised computer every minute. |
| Used by | Procedure example |
|---|---|
| MalwareAgent Tesla | Agent Tesla can capture screenshots of the victim’s desktop. |
| MalwareAppleSeed | AppleSeed can take screenshots on a compromised host by calling a series of APIs. |
| MalwareAria-body | Aria-body has the ability to capture screenshots on compromised hosts. |
| MalwareAshTag | The AshTag AshenOrchestrator component has the ability to take screenshots. |
| ToolAsyncRAT | AsyncRAT has the ability to view the screen on compromised hosts. |
| MalwareAttor | Attor's has a plugin that captures screenshots of the target applications. |
| MalwareAzorult | Azorult can capture screenshots of the victim’s machines. |
| MalwareBADHATCH | BADHATCH can take screenshots and send them to an actor-controlled C2 server. |
View all 151 software examples
| Used by | Procedure example |
|---|---|
| Campaign2025 Poland Wiper Attacks | During the 2025 Poland Wiper Attacks, the adversaries captured screenshots of devices using |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.