ATT&CKProcedure examples

Procedure examples

Real-world descriptions of how a group, tool or campaign used a technique.

Technique: T1056.001×

126 examples

TechniqueUsed byProcedure example
T1056.001
Keylogging
MalwareAgent Tesla

Agent Tesla can log keystrokes on the victim’s machine.

T1056.001
Keylogging
MalwareECCENTRICBANDWAGON

ECCENTRICBANDWAGON can capture and store keystrokes.

T1056.001
Keylogging
MalwareBADNEWS

When it first starts, BADNEWS spawns a new thread to log keystrokes.

T1056.001
Keylogging
MalwareDRYHOOK

DRYHOOK has captured user credentials and passwords in plaintext and has encrypted them in a stored file on the network device.

T1056.001
Keylogging
MalwareRemexi

Remexi gathers and exfiltrates keystrokes from the machine.

T1056.001
Keylogging
MalwareAstaroth

Astaroth logs keystrokes from the victim's machine.

T1056.001
Keylogging
MalwareQakBot

QakBot can capture keystrokes on a compromised host.

T1056.001
Keylogging
MalwarejRAT

jRAT has the capability to log keystrokes from the victim’s machine, both offline and online.

T1056.001
Keylogging
MalwareHelminth

The executable version of Helminth has a module to log keystrokes.

T1056.001
Keylogging
MalwareMacSpy

MacSpy captures keystrokes.

T1056.001
Keylogging
MalwareDtrack

Dtrack’s dropper contains a keylogging executable.

T1056.001
Keylogging
MalwareADVSTORESHELL

ADVSTORESHELL can perform keylogging.

T1056.001
Keylogging
MalwareWarzoneRAT

WarzoneRAT has the capability to install a live and offline keylogger, including through the use of the `GetAsyncKeyState` Windows API.

T1056.001
Keylogging
MalwareSLOTHFULMEDIA

SLOTHFULMEDIA has a keylogging capability.

T1056.001
Keylogging
ToolSILENTTRINITY

SILENTTRINITY has a keylogging capability.

T1056.001
Keylogging
ToolPowerSploit

PowerSploit's Get-Keystrokes Exfiltration module can log keystrokes.

T1056.001
Keylogging
ToolDCRAT

DCRAT can log keystrokes on targeted systems.

T1056.001
Keylogging
ToolEmpire

Empire includes keylogging capabilities for Windows, Linux, and macOS systems.

T1056.001
Keylogging
ToolPcShare

PcShare has the ability to capture keystrokes.

T1056.001
Keylogging
ToolPoshC2

PoshC2 has modules for keystroke logging and capturing credentials from spoofed Outlook authentication messages.

T1056.001
Keylogging
ToolAsyncRAT

AsyncRAT can capture keystrokes on the victim’s machine.

T1056.001
Keylogging
ToolRemcos

Remcos has a command for keylogging.

T1056.001
Keylogging
ToolImminent Monitor

Imminent Monitor has a keylogging module.

T1056.001
Keylogging
ToolPupy

Pupy uses a keylogger to capture keystrokes it then sends back to the server after it is stopped.

T1056.001
Keylogging
ToolQuasarRAT

QuasarRAT has a built-in keylogger.

T1056.001
Keylogging
MalwareDuqu

Duqu can track key presses with a keylogger module.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.