Threaticon
Toggle sidebar

You're viewing a limited, public preview. Log in for full access.

Log in User Guide
Log in Get started
Attack Patterns T1113 — Screen Capture
T1113

Screen Capture

Collection
TLP:CLEAR

Description

Adversaries may attempt to take screen captures of the desktop to gather information over the course of an operation. Screen capturing functionality may be included as a feature of a remote access tool used in post-compromise operations. Taking a screenshot is also typically possible through native utilities or API calls, such as <code>CopyFromScreen</code>, <code>xwd</code>, or <code>screencapture</code>.(Citation: CopyFromScreen .NET)(Citation: Antiquated Mac Malware)

MITRE ATT&CK Detection Strategies
1

DET0346 Detect Screen Capture via Commands and API Calls
AN0982 Linux

Use of tools like xwd or import to generate screenshots, especially under non-GUI parent processes.

auditd:SYSCALL
AN0980 Windows

Unusual use of screen capture APIs (e.g., CopyFromScreen) or command-line tools to write image files to disk.

WinEventLog:Sysmon WinEventLog:Sysmon
AN0981 macOS

Invocation of built-in commands like screencapture or use of undocumented APIs from suspicious parent processes.

macos:unifiedlog

Details

Platforms
Linux
Macos
Windows
Added
May 2, 2026
Leaving Threaticon

This link opens an external site that isn't part of the platform.