Real-world descriptions of how a group, tool or campaign used a technique.
17136 examples
| Technique | Used by | Procedure example |
|---|---|---|
| T1056.001 Keylogging |
MalwareBlackEnergy | BlackEnergy has run a keylogger plug-in on a victim. |
| T1056.001 Keylogging |
MalwareXAgentOSX | XAgentOSX contains keylogging functionality that will monitor for active application windows and write them to the log, it can handle special characters, and it will buffer by default 50 characters before sending them out over the C2 infrastructure. |
| T1056.001 Keylogging |
MalwareKeyBoy | KeyBoy installs a keylogger for intercepting credentials and keystrokes. |
| T1056.001 Keylogging |
MalwareDarkTortilla | DarkTortilla can download a keylogging module. |
| T1056.001 Keylogging |
MalwareROKRAT | ROKRAT can use `SetWindowsHookEx` and `GetKeyNameText` to capture keystrokes. |
| T1056.001 Keylogging |
MalwareRunningRAT | RunningRAT captures keystrokes and sends them back to the C2 server. |
| T1056.001 Keylogging |
MalwareDarkWatchman | DarkWatchman can track key presses with a keylogger module. |
| T1056.001 Keylogging |
MalwarePlugX | PlugX has a module for capturing keystrokes per process including window titles. |
| T1056.001 Keylogging |
MalwareDustySky | DustySky contains a keylogger. |
| T1056.001 Keylogging |
MalwareRemsec | Remsec contains a keylogger component. |
| T1056.001 Keylogging |
MalwareSykipot | Sykipot contains keylogging functionality to steal passwords. |
| T1056.001 Keylogging |
MalwareExplosive | Explosive has leveraged its keylogging capabilities to gain access to administrator accounts on target servers. |
| T1056.001 Keylogging |
MalwareRover | Rover has keylogging functionality. |
| T1056.001 Keylogging |
MalwarePeppy | Peppy can log keystrokes on compromised hosts. |
| T1056.001 Keylogging |
MalwareCuba | Cuba logs keystrokes via polling by using |
| T1056.001 Keylogging |
MalwareClambling | Clambling can capture keystrokes on a compromised host. |
| T1056.001 Keylogging |
MalwareDarkGate | DarkGate will spawn a thread on execution to capture all keyboard events and write them to a predefined log file. |
| T1056.001 Keylogging |
MalwareThiefQuest | ThiefQuest uses the |
| T1056.001 Keylogging |
MalwareCarbanak | Carbanak logs key strokes for configured processes and sends them back to the C2 server. |
| T1056.001 Keylogging |
MalwareLODEINFO | LODEINFO can capture keystrokes on targeted systems. |
| T1056.001 Keylogging |
MalwareSMOKEDHAM | SMOKEDHAM can continuously capture keystrokes. |
| T1056.001 Keylogging |
MalwareMetamorfo | Metamorfo has a command to launch a keylogger and capture keystrokes on the victim’s machine. |
| T1056.001 Keylogging |
MalwareTrojan.Karagany | Trojan.Karagany can capture keystrokes on a compromised host. |
| T1056.001 Keylogging |
MalwareBandook | Bandook contains keylogging capabilities. |
| T1056.001 Keylogging |
MalwareKONNI | KONNI has the capability to perform keylogging. |
| T1056.001 Keylogging |
Malwaregh0st RAT | gh0st RAT has a keylogger. |
| T1056.001 Keylogging |
MalwareKGH_SPY | KGH_SPY can perform keylogging by polling the |
| T1056.001 Keylogging |
MalwareMicropsia | Micropsia has keylogging capabilities. |
| T1056.001 Keylogging |
MalwareCatchamas | Catchamas collects keystrokes from the victim’s machine. |
| T1056.001 Keylogging |
MalwareAttor | One of Attor's plugins can collect user credentials via capturing keystrokes and can capture keystrokes pressed within the window of the injected process. |
| T1056.001 Keylogging |
MalwareNightClub | NightClub can use a plugin for keylogging. |
| T1056.001 Keylogging |
MalwareRTM | RTM can record keystrokes from both the keyboard and virtual keyboard. |
| T1056.001 Keylogging |
MalwareDerusbi | Derusbi is capable of logging keystrokes. |
| T1056.001 Keylogging |
MalwareGrandoreiro | Grandoreiro can log keystrokes on the victim's machine. |
| T1056.001 Keylogging |
MalwareBadPatch | BadPatch has a keylogging capability. |
| T1056.001 Keylogging |
MalwareXLoader | XLoader can capture keystrokes from the victim machine. |
| T1056.001 Keylogging |
MalwareMoonWind | MoonWind has a keylogger. |
| T1056.001 Keylogging |
MalwareCorKLOG | CorKLOG has captured keystrokes. |
| T1056.001 Keylogging |
MalwareMgBot | MgBot includes keylogger payloads focused on the QQ chat application. |
| T1056.001 Keylogging |
MalwareOwaAuth | OwaAuth captures and DES-encrypts credentials before writing the username and password to a log file, |
| T1056.001 Keylogging |
MalwareCadelspy | Cadelspy has the ability to log keystrokes on the compromised host. |
| T1056.001 Keylogging |
MalwareCobalt Strike | Cobalt Strike can track key presses with a keylogger module. |
| T1056.001 Keylogging |
MalwareCobian RAT | Cobian RAT has a feature to perform keylogging on the victim’s machine. |
| T1056.001 Keylogging |
MalwareUnknown Logger | Unknown Logger is capable of recording keystrokes. |
| T1056.001 Keylogging |
MalwareKivars | Kivars has the ability to initiate keylogging on the infected host. |
| T1056.001 Keylogging |
MalwarePoisonIvy | PoisonIvy contains a keylogger. |
| T1056.001 Keylogging |
MalwareNanoCore | NanoCore can perform keylogging on the victim’s machine. |
| T1056.001 Keylogging |
MalwareTajMahal | TajMahal has the ability to capture keystrokes on an infected host. |
| T1056.001 Keylogging |
MalwareDaserf | Daserf can log keystrokes. |
| T1056.001 Keylogging |
MalwareCardinal RAT | Cardinal RAT can log keystrokes. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.