ATT&CKProcedure examples

Procedure examples

Real-world descriptions of how a group, tool or campaign used a technique.

17136 examples

TechniqueUsed byProcedure example
T1056.001
Keylogging
MalwareBISCUIT

BISCUIT can capture keystrokes.

T1056.001
Keylogging
MalwareFakeM

FakeM contains a keylogger module.

T1056.001
Keylogging
MalwareRevenge RAT

Revenge RAT has a plugin for keylogging.

T1056.001
Keylogging
MalwareMacMa

MacMa can use Core Graphics Event Taps to intercept user keystrokes from any text input field and saves them to text files. Text input fields include Spotlight, Finder, Safari, Mail, Messages, and other apps that have text fields for passwords.

T1056.001
Keylogging
MalwareFunnyDream

The FunnyDream Keyrecord component can capture keystrokes.

T1056.001
Keylogging
MalwareTinyZBot

TinyZBot contains keylogger functionality.

T1056.001
Keylogging
MalwareProton

Proton uses a keylogger to capture keystrokes.

T1056.001
Keylogging
MalwareNetTraveler

NetTraveler contains a keylogger.

T1056.001
Keylogging
MalwareLokibot

Lokibot has the ability to capture input on the compromised host via keylogging.

T1056.001
Keylogging
MalwarePoetRAT

PoetRAT has used a Python tool named klog.exe for keylogging.

T1056.001
Keylogging
MalwareCHOPSTICK

CHOPSTICK is capable of performing keylogging.

T1056.001
Keylogging
MalwareZxShell

ZxShell has a feature to capture a remote computer's keystrokes using a keylogger.

T1056.001
Keylogging
MalwareBabyShark

BabyShark has a PowerShell-based remote administration ability that can implement a PowerShell or C# based keylogger.

T1056.001
Keylogging
MalwarenjRAT

njRAT is capable of logging keystrokes.

T1056.001
Keylogging
MalwareJPIN

JPIN contains a custom keylogger.

T1056.001
Keylogging
MalwaremetaMain

metaMain has the ability to log keyboard events.

T1056.001
Keylogging
MalwareHTTPBrowser

HTTPBrowser is capable of capturing keystrokes on victims.

T1056.001
Keylogging
MalwareAgent Tesla

Agent Tesla can log keystrokes on the victim’s machine.

T1056.001
Keylogging
MalwareECCENTRICBANDWAGON

ECCENTRICBANDWAGON can capture and store keystrokes.

T1056.001
Keylogging
MalwareBADNEWS

When it first starts, BADNEWS spawns a new thread to log keystrokes.

T1056.001
Keylogging
MalwareDRYHOOK

DRYHOOK has captured user credentials and passwords in plaintext and has encrypted them in a stored file on the network device.

T1056.001
Keylogging
MalwareRemexi

Remexi gathers and exfiltrates keystrokes from the machine.

T1056.001
Keylogging
MalwareAstaroth

Astaroth logs keystrokes from the victim's machine.

T1056.001
Keylogging
MalwareQakBot

QakBot can capture keystrokes on a compromised host.

T1056.001
Keylogging
MalwarejRAT

jRAT has the capability to log keystrokes from the victim’s machine, both offline and online.

T1056.001
Keylogging
MalwareHelminth

The executable version of Helminth has a module to log keystrokes.

T1056.001
Keylogging
MalwareMacSpy

MacSpy captures keystrokes.

T1056.001
Keylogging
MalwareDtrack

Dtrack’s dropper contains a keylogging executable.

T1056.001
Keylogging
MalwareADVSTORESHELL

ADVSTORESHELL can perform keylogging.

T1056.001
Keylogging
MalwareWarzoneRAT

WarzoneRAT has the capability to install a live and offline keylogger, including through the use of the `GetAsyncKeyState` Windows API.

T1056.001
Keylogging
MalwareSLOTHFULMEDIA

SLOTHFULMEDIA has a keylogging capability.

T1056.001
Keylogging
ToolSILENTTRINITY

SILENTTRINITY has a keylogging capability.

T1056.001
Keylogging
ToolPowerSploit

PowerSploit's Get-Keystrokes Exfiltration module can log keystrokes.

T1056.001
Keylogging
ToolDCRAT

DCRAT can log keystrokes on targeted systems.

T1056.001
Keylogging
ToolEmpire

Empire includes keylogging capabilities for Windows, Linux, and macOS systems.

T1056.001
Keylogging
ToolPcShare

PcShare has the ability to capture keystrokes.

T1056.001
Keylogging
ToolPoshC2

PoshC2 has modules for keystroke logging and capturing credentials from spoofed Outlook authentication messages.

T1056.001
Keylogging
ToolAsyncRAT

AsyncRAT can capture keystrokes on the victim’s machine.

T1056.001
Keylogging
ToolRemcos

Remcos has a command for keylogging.

T1056.001
Keylogging
ToolImminent Monitor

Imminent Monitor has a keylogging module.

T1056.001
Keylogging
ToolPupy

Pupy uses a keylogger to capture keystrokes it then sends back to the server after it is stopped.

T1056.001
Keylogging
ToolQuasarRAT

QuasarRAT has a built-in keylogger.

T1056.001
Keylogging
MalwareDuqu

Duqu can track key presses with a keylogger module.

T1056.002
GUI Input Capture
GroupRedCurl

RedCurl prompts the user for credentials through a Microsoft Outlook pop-up.

T1056.002
GUI Input Capture
GroupFIN4

FIN4 has presented victims with spoofed Windows Authentication prompts to collect their credentials.

T1056.002
GUI Input Capture
MalwareiKitten

iKitten prompts the user for their credentials.

T1056.002
GUI Input Capture
MalwareCuckoo Stealer

Cuckoo Stealer has captured passwords by prompting victims with a “macOS needs to access System Settings” GUI window.

T1056.002
GUI Input Capture
MalwareKeydnap

Keydnap prompts the users for credentials.

T1056.002
GUI Input Capture
MalwareMispadu

Mispadu can monitor browser activity for online banking actions and display full-screen overlay images to block user access to the intended site or present additional data fields.

T1056.002
GUI Input Capture
MalwareMuddyViper

MuddyViper has displayed a fake Windows Security dialog to gather credentials.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.