MITRE ATT&CK technique
Input Capture detection rulesT1056
Input Capture (T1056) is a MITRE ATT&CK technique in the Credential Access tactic. This page lists the 8 community-maintained Sigma detection rules in the library mapped to T1056 and its sub-techniques. Each rule includes its detection logic, log source, false positives and original YAML. These rules mainly target windows, linux, macos.
Tactic
Linux Keylogging with Pam.d
highDetect attempt to enable auditing of TTY input
linux
CredUI.DLL Loaded By Uncommon Process
mediumDetects loading of "credui.dll" and related DLLs by an uncommon process. Attackers might leverage this DLL for potential use of "CredUIPromptForCredentials" or "CredUnPackAuthenticationBufferW".
windows · image_load
Potential Keylogger Activity
mediumDetects PowerShell scripts that contains reference to keystroke capturing functions
windows · ps_script
Powershell Keylogging
mediumAdversaries may log user keystrokes to intercept credentials as the user types them.
windows · ps_script
PUA - Mouse Lock Execution
mediumIn Kaspersky's 2020 Incident Response Analyst Report they listed legitimate tool "Mouse Lock" as being used for both credential access and collection in security incidents.
windows · process_creation
DNS Query Request To OneLaunch Update Service
lowDetects DNS query requests to "update.onelaunch.com". This domain is associated with the OneLaunch adware application. When the OneLaunch application is installed it will attempt to get updates from this domain.
windows · dns_query
GUI Input Capture - macOS
lowDetects attempts to use system dialog prompts to capture user credentials
macos · process_creation
Suspicious Network Communication With IPFS
lowDetects connections to interplanetary file system (IPFS) containing a user's email address which mirrors behaviours observed in recent phishing campaigns leveraging IPFS to host credential harvesting webpages.
proxy