T1113 Screen Capture — ATT&CK Technique
Adversaries may attempt to take screen captures of the desktop to gather information over the course of an operation. Screen capturing functionality may be included as a feature of a remote access tool used in post-compromise operations. Taking a screenshot is also typically possible through native utilities or API calls, such as CopyFromScreen, xwd, or screencapture.
Detection coverage (15)
- System Drawing DLL Load low
- Screen Capture with Import Tool low
- Screen Capture with Xwd low
- Screen Capture Activity Via Psr.EXE medium
- Screen Capture - macOS low
- Windows Recall Feature Enabled Via Reg.EXE medium
- Windows Screen Capture with CopyFromScreen medium
- Windows Recall Feature Enabled - DisableAIDataAnalysis Value Deleted medium
- Windows Recall Feature Enabled - Registry medium
- Periodic Backup For System Registry Hives Enabled medium
- Remcos RAT File Creation in Remcos Folder
- Suspicious Image Creation In Appdata Folder
- Suspicious WAV file in Appdata Folder
- Windows Screen Capture Via Powershell
- Windows Screen Capture in TEMP folder
Malware using this technique
- RCSession
- QuietSieve
- GRIFFON
- yty
- DOGCALL
- Bandook
- SharpStage
- HALFBAKED
- KEYMARBLE
- Ursnif
- ZLib
- RedLeaves
- Zeus Panda
- Havoc
- Chrommme
- ObliqueRAT
- Matryoshka
- Janicab
- TONESHELL
- Kasidet
- RainyDay
- AppleSeed
- NETWIRE
- LitePower
- CosmicDuke
- EvilGrab
- Aria-body
- Crimson
- DUSTTRAP
- Turian
- BADHATCH
- Machete
- Prikormka
- Woody RAT
- Mafalda
- SHUTTERSPEED
- FlawedAmmyy
- Cuckoo Stealer
- InvisiMole
- FruitFly
- RDAT
- TRANSLATEXT
- Mispadu
- VERMIN
- HTTPTroy
- MarkiRAT
- Kazuar
- POORAIM
- CHIMNEYSWEEP
- BlackEnergy