T1113 Screen Capture — ATT&CK Technique
Adversaries may attempt to take screen captures of the desktop to gather information over the course of an operation. Screen capturing functionality may be included as a feature of a remote access tool used in post-compromise operations. Taking a screenshot is also typically possible through native utilities or API calls, such as CopyFromScreen, xwd, or screencapture.
Detection coverage (15)
- System Drawing DLL Load low
- Screen Capture with Import Tool low
- Screen Capture with Xwd low
- Screen Capture Activity Via Psr.EXE medium
- Screen Capture - macOS low
- Windows Recall Feature Enabled Via Reg.EXE medium
- Windows Screen Capture with CopyFromScreen medium
- Windows Recall Feature Enabled - DisableAIDataAnalysis Value Deleted medium
- Windows Recall Feature Enabled - Registry medium
- Periodic Backup For System Registry Hives Enabled medium
- Remcos RAT File Creation in Remcos Folder
- Suspicious Image Creation In Appdata Folder
- Suspicious WAV file in Appdata Folder
- Windows Screen Capture Via Powershell
- Windows Screen Capture in TEMP folder
Malware using this technique
- AshTag
- Pteranodon
- GRIFFON
- JHUHUGIT
- Agent Tesla
- Pupy
- TURNEDUP
- Trojan.Karagany
- FinFisher
- XLoader
- Cobian RAT
- BADNEWS
- Ramsay
- BlackEnergy
- Troll Stealer
- Carbanak
- TONESHELL
- ObliqueRAT
- Clambling
- Lumma Stealer
- PcShare
- Empire
- Mispadu
- CrossRAT
- Prikormka
- BISCUIT
- UPPERCUT
- Brute Ratel C4
- MacMa
- BADHATCH
- LightSpy
- njRAT
- DUSTTRAP
- Turian
- Havoc
- Cannon
- Zebrocy
- TajMahal
- Cobalt Strike
- SharpStage
- InvisiMole
- RedLeaves
- SILENTTRINITY
- RDAT
- Zeus Panda
- ZxShell
- POORAIM
- RCSession
- LitePower
- BadPatch