T1056.001 Keylogging
Subtécnica de T1056 Input Capture
Adversaries may log user keystrokes to intercept credentials as the user types them. Keylogging is likely to be used to acquire credentials for new access opportunities when [OS Credential Dumping](https://attack.mitre.org/techniques/T1003) efforts are not effective, and may require an adversary to intercept keystrokes on a system for a substantial period of time before credentials can be…
Quién la usa · con noticias en Jábega
Reglas Sigma para cazarla
- Linux Keylogging with Pam.dhightest · linux
- Potential Keylogger Activitymediumtest · windows
- Powershell Keyloggingmediumtest · windows
Reglas de SigmaHQ · Detection Rule License 1.1. Técnica de MITRE ATT&CK®.