Application Window Discovery

T1010

Technique.View on attack.mitre.org

About this technique

Adversaries may attempt to get a listing of open application windows. Window listings could convey information about how the system is used. For example, information about application windows could be used identify potential data to collect as well as identifying security tooling (Security Software Discovery) to evade.

Adversaries typically abuse system features for this type of enumeration. For example, they may gather information through native system features such as Command and Scripting Interpreter commands and Native API functions.

Detection rules1

Rules on DetectionCode tagged with T1010.

Sigma1

RuleLevelLog source
SCM Database Handle Failuremediumwindows / NULL

Splunk0

No Splunk rules are mapped to this technique yet.

Groups3

Software34

Show 10 more

Campaigns0

None recorded.

Procedure examples37

Groups3

Used byProcedure example
GroupHEXANE

HEXANE has used a PowerShell-based keylogging tool to capture the window title.

GroupLazarus Group

Lazarus Group malware IndiaIndia obtains and sends to its C2 server the title of the window for each running process. The KilaAlfa keylogger also reports the title of the window in the foreground.

GroupVolt Typhoon

Volt Typhoon has collected window title information from compromised systems.

Software34

Used byProcedure example
MalwareAria-body

Aria-body has the ability to identify the titles of running windows on a compromised host.

MalwareAttor

Attor can obtain application window titles and then determines which windows to perform Screen Capture on.

MalwareCadelspy

Cadelspy has the ability to identify open windows on the compromised host.

MalwareCatchamas

Catchamas obtains application windows titles and then determines which windows to perform Screen Capture on.

MalwareDarkGate

DarkGate will search for cryptocurrency wallets by examining application window names for specific strings. DarkGate extracts information collected via NirSoft tools from the hosting process's memory by first identifying the window through the FindWindow API function.

MalwareDarkWatchman

DarkWatchman reports window names along with keylogger information to provide application context.

MalwareDuqu

The discovery modules used with Duqu can collect information on open windows.

MalwareDUSTTRAP

DUSTTRAP can enumerate running application windows.

View all 34 software examples

References2

  1. ESET Grandoreiro April 2020 Open source
    ESET. (2020, April 28). Grandoreiro: How engorged can an EXE get?. Retrieved November 13, 2020.
  2. Prevailion DarkWatchman 2021 Open source
    Smith, S., Stafford, M. (2021, December 14). DarkWatchman: A new evolution in fileless techniques. Retrieved January 10, 2022.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.