This website uses cookies to ensure you get the best experience.
Got it!
Register
|
Login
Menu
Home
Sigma Rules
Splunk Rules
Explore Rules
Analytic Stories
MITRE ATT&CK
Overview
Matrix
Techniques
Groups
Software
Campaigns
Search
About
Potential Keylogger Activity
Original Source:
[Sigma source]
Title:
Potential Keylogger Activity
Status:
test
Description:
Detects PowerShell scripts that contains reference to keystroke capturing functions
References:
-https://twitter.com/ScumBots/status/1610626724257046529
-https://www.virustotal.com/gui/file/d4486b63512755316625230e0c9c81655093be93876e0d80732e7eeaf7d83476/content
-https://www.virustotal.com/gui/file/720a7ee9f2178c70501d7e3f4bcc28a4f456e200486dbd401b25af6da3b4da62/content
-https://learn.microsoft.com/en-us/dotnet/api/system.windows.input.keyboard.iskeydown?view=windowsdesktop-7.0
Author:
Nasreddine Bencherchali (Nextron Systems)
Date:
2023-01-04
modified:
None
Tags:
-'attack.collection'
-'attack.credential-access'
-'attack.t1056.001'
Logsource:
product: windows
category: ps_script
definition: Requirements: Script Block Logging must be enabled
Detection:
selection:
ScriptBlockText|contains
:
'[Windows.Input.Keyboard]::IsKeyDown([System.Windows.Input.Key]::'
condition
:
selection
Falsepositives:
-Unknown
Level:
medium