Screen Capture

T1113

Technique.View on attack.mitre.org

About this technique

Adversaries may attempt to take screen captures of the desktop to gather information over the course of an operation. Screen capturing functionality may be included as a feature of a remote access tool used in post-compromise operations. Taking a screenshot is also typically possible through native utilities or API calls, such as CopyFromScreen, xwd, or screencapture.

Detection rules14

Rules on DetectionCode tagged with T1113.

Sigma9

RuleLevelLog source
Periodic Backup For System Registry Hives Enabledmediumwindows / registry_set
Screen Capture Activity Via Psr.EXEmediumwindows / process_creation
Windows Recall Feature Enabled - DisableAIDataAnalysis Value Deletedmediumwindows / registry_delete
Windows Recall Feature Enabled - Registrymediumwindows / registry_set
Windows Recall Feature Enabled Via Reg.EXEmediumwindows / process_creation
Windows Screen Capture with CopyFromScreenmediumwindows / ps_script
Screen Capture - macOSlowmacos / process_creation
Screen Capture with Import Toollowlinux / NULL
Screen Capture with Xwdlowlinux / NULL

Splunk5

RuleTypeRiskData source
Remcos RAT File Creation in Remcos FolderTTPNULLSysmon EventID 11
Suspicious Image Creation In Appdata FolderTTPNULLSysmon EventID 1 AND Sysmon EventID 11
Suspicious WAV file in Appdata FolderTTPNULLSysmon EventID 1 AND Sysmon EventID 11, Windows Event Log Security 4688 AND Sysmon EventID 11
Windows Screen Capture in TEMP folderTTPNULLSysmon EventID 11
Windows Screen Capture Via PowershellTTPNULLPowershell Script Block Logging 4104

Groups19

Software151

Show 127 more

Campaigns1

Procedure examples171

Groups19

Used byProcedure example
GroupAPT28

APT28 has used tools to take screenshots from victims.

GroupAPT39

APT39 has used a screen capture utility to take screenshots on a compromised host.

GroupAPT42

APT42 has used malware, such as GHAMBAR and POWERPOST, to take screenshots.

GroupBRONZE BUTLER

BRONZE BUTLER has used a tool to capture screenshots.

GroupDark Caracal

Dark Caracal took screenshots using their Windows malware.

GroupDragonfly

Dragonfly has performed screen captures of victims, including by using a tool, scr.exe (which matched the hash of ScreenUtil).

GroupFIN7

FIN7 captured screenshots and desktop video recordings.

GroupGamaredon Group

Gamaredon Group's malware can take screenshots of the compromised computer every minute.

View all 19 groups examples

Software151

Used byProcedure example
MalwareAgent Tesla

Agent Tesla can capture screenshots of the victim’s desktop.

MalwareAppleSeed

AppleSeed can take screenshots on a compromised host by calling a series of APIs.

MalwareAria-body

Aria-body has the ability to capture screenshots on compromised hosts.

MalwareAshTag

The AshTag AshenOrchestrator component has the ability to take screenshots.

ToolAsyncRAT

AsyncRAT has the ability to view the screen on compromised hosts.

MalwareAttor

Attor's has a plugin that captures screenshots of the target applications.

MalwareAzorult

Azorult can capture screenshots of the victim’s machines.

MalwareBADHATCH

BADHATCH can take screenshots and send them to an actor-controlled C2 server.

View all 151 software examples

Campaigns1

Used byProcedure example
Campaign2025 Poland Wiper Attacks

During the 2025 Poland Wiper Attacks, the adversaries captured screenshots of devices using nircmd console through the command nircmd.exe “savescreenshot C:\Windows\Temp\imagetmp.png.

References2

  1. Antiquated Mac Malware Open source
    Thomas Reed. (2017, January 18). New Mac backdoor using antiquated code. Retrieved July 5, 2017.
  2. CopyFromScreen .NET Open source
    Microsoft. (n.d.). Graphics.CopyFromScreen Method. Retrieved March 24, 2020.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.