T1113 Screen Capture — ATT&CK Technique

Adversaries may attempt to take screen captures of the desktop to gather information over the course of an operation. Screen capturing functionality may be included as a feature of a remote access tool used in post-compromise operations. Taking a screenshot is also typically possible through native utilities or API calls, such as CopyFromScreen, xwd, or screencapture.

Detection coverage (15)

Malware using this technique

Threat actors using this technique

Read the full analysis on IntelFusions