Input Capture

T1056

Technique with 4 sub-techniques.View on attack.mitre.org

About this technique

Adversaries may use methods of capturing user input to obtain credentials or collect information. During normal system usage, users often provide credentials to various different locations, such as login pages/portals or system dialog boxes. Input capture mechanisms may be transparent to the user (e.g. Credential API Hooking) or rely on deceiving the user into providing input into what they believe to be a genuine service (e.g. Web Portal Capture).

Detection rules10

Rules on DetectionCode tagged with T1056 or one of its sub-techniques.

Sigma8

RuleLevelLog sourceTechnique
Linux Keylogging with Pam.dhighlinux / NULLT1056.001
CredUI.DLL Loaded By Uncommon Processmediumwindows / image_loadT1056.002
Potential Keylogger Activitymediumwindows / ps_scriptT1056.001
Powershell Keyloggingmediumwindows / ps_scriptT1056.001
PUA - Mouse Lock Executionmediumwindows / process_creationT1056.002
DNS Query Request To OneLaunch Update Servicelowwindows / dns_queryT1056
GUI Input Capture - macOSlowmacos / process_creationT1056.002
Suspicious Network Communication With IPFSlowNULL / proxyT1056

Splunk2

RuleTypeRiskData sourceTechnique
MacOS Osascript Displaying Suspicious User PromptAnomalyNULLOsquery ResultsT1056.002
Windows Input Capture Using Credential UI DllHuntingNULLSysmon EventID 7T1056.002

Sub-techniques4

IDNameExamples
T1056.001Keylogging155
T1056.002GUI Input Capture15
T1056.003Web Portal Capture6
T1056.004Credential API Hooking12

Groups3

Software7

Campaigns2

Procedure examples12

Groups3

Used byProcedure example
GroupAPT39

APT39 has utilized tools to capture mouse movements.

GroupAPT42

APT42 has used credential harvesting websites.

GroupStorm-1811

Storm-1811 has used a PowerShell script to capture user credentials after prompting a user to authenticate to run a malicious script masquerading as a legitimate update item.

Software7

Used byProcedure example
MalwareChaes

Chaes has a module to perform any API hooking it desires.

MalwareFlawedAmmyy

FlawedAmmyy can collect mouse events.

MalwareInvisibleFerret

InvisibleFerret has collected mouse and keyboard events using “pyWinhook”.

MalwareKobalos

Kobalos has used a compromised SSH client to capture the hostname, port, username and password used to establish an SSH connection from the compromised host.

MalwareMafalda

Mafalda can conduct mouse event logging.

MalwaremetaMain

metaMain can log mouse events.

ToolNPPSPY

NPPSPY captures user input into the Winlogon process by redirecting RPC traffic from legitimate listening DLLs within the operating system to a newly registered malicious item that allows for recording logon information in cleartext.

Campaigns2

Used byProcedure example
CampaignLeviathan Australian Intrusions

Leviathan captured submitted multfactor authentication codes and other technical artifacts related to remote access sessions during Leviathan Australian Intrusions.

CampaignVersa Director Zero Day Exploitation

Versa Director Zero Day Exploitation intercepted and harvested credentials from user logins to compromised devices.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.