Real-world descriptions of how a group, tool or campaign used a technique.
126 examples
| Technique | Used by | Procedure example |
|---|---|---|
| T1056.001 Keylogging |
MalwareAgent Tesla | Agent Tesla can log keystrokes on the victim’s machine. |
| T1056.001 Keylogging |
MalwareECCENTRICBANDWAGON | ECCENTRICBANDWAGON can capture and store keystrokes. |
| T1056.001 Keylogging |
MalwareBADNEWS | When it first starts, BADNEWS spawns a new thread to log keystrokes. |
| T1056.001 Keylogging |
MalwareDRYHOOK | DRYHOOK has captured user credentials and passwords in plaintext and has encrypted them in a stored file on the network device. |
| T1056.001 Keylogging |
MalwareRemexi | Remexi gathers and exfiltrates keystrokes from the machine. |
| T1056.001 Keylogging |
MalwareAstaroth | Astaroth logs keystrokes from the victim's machine. |
| T1056.001 Keylogging |
MalwareQakBot | QakBot can capture keystrokes on a compromised host. |
| T1056.001 Keylogging |
MalwarejRAT | jRAT has the capability to log keystrokes from the victim’s machine, both offline and online. |
| T1056.001 Keylogging |
MalwareHelminth | The executable version of Helminth has a module to log keystrokes. |
| T1056.001 Keylogging |
MalwareMacSpy | MacSpy captures keystrokes. |
| T1056.001 Keylogging |
MalwareDtrack | Dtrack’s dropper contains a keylogging executable. |
| T1056.001 Keylogging |
MalwareADVSTORESHELL | ADVSTORESHELL can perform keylogging. |
| T1056.001 Keylogging |
MalwareWarzoneRAT | WarzoneRAT has the capability to install a live and offline keylogger, including through the use of the `GetAsyncKeyState` Windows API. |
| T1056.001 Keylogging |
MalwareSLOTHFULMEDIA | SLOTHFULMEDIA has a keylogging capability. |
| T1056.001 Keylogging |
ToolSILENTTRINITY | SILENTTRINITY has a keylogging capability. |
| T1056.001 Keylogging |
ToolPowerSploit | PowerSploit's |
| T1056.001 Keylogging |
ToolDCRAT | DCRAT can log keystrokes on targeted systems. |
| T1056.001 Keylogging |
ToolEmpire | Empire includes keylogging capabilities for Windows, Linux, and macOS systems. |
| T1056.001 Keylogging |
ToolPcShare | PcShare has the ability to capture keystrokes. |
| T1056.001 Keylogging |
ToolPoshC2 | PoshC2 has modules for keystroke logging and capturing credentials from spoofed Outlook authentication messages. |
| T1056.001 Keylogging |
ToolAsyncRAT | AsyncRAT can capture keystrokes on the victim’s machine. |
| T1056.001 Keylogging |
ToolRemcos | Remcos has a command for keylogging. |
| T1056.001 Keylogging |
ToolImminent Monitor | Imminent Monitor has a keylogging module. |
| T1056.001 Keylogging |
ToolPupy | Pupy uses a keylogger to capture keystrokes it then sends back to the server after it is stopped. |
| T1056.001 Keylogging |
ToolQuasarRAT | QuasarRAT has a built-in keylogger. |
| T1056.001 Keylogging |
MalwareDuqu | Duqu can track key presses with a keylogger module. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.