Threaticon
Toggle sidebar

You're viewing a limited, public preview. Log in for full access.

Log in User Guide
Log in Get started
Detection Strategies DET0102 — Behavioral Detection of Input Capture Across Platforms
DET0102

Behavioral Detection of Input Capture Across Platforms

4 analytic(s) · 1 technique(s) detected

Analytics

4
AN0282 Analytic 0282
Windows

Monitors for abnormal process behavior and API calls like SetWindowsHookEx, GetAsyncKeyState, or device input polling commonly used for keystroke logging.

WinEventLog:Sysmon EventCode=10 WinEventLog:Security EventCode=4663, 4670, 4656
[TargetImage] Can be scoped to sensitive GUI processes like explorer.exe or winlogon.exe
[TimeWindow] Time threshold for detecting multiple suspicious accesses
AN0283 Analytic 0283
Linux

Detects use of tools/scripts accessing input devices like /dev/input/* or evdev via suspicious processes lacking GUI context.

auditd:SYSCALL open, read auditd:SYSCALL write auditd:SYSCALL ptrace, ioctl
[ProcessName] Unusual process accessing device files
[DevicePath] Typically /dev/input/*, but tunable to exact endpoint config
AN0284 Analytic 0284
macOS

Monitors for TCC-bypassing or unauthorized access to input services like IOHIDSystem or Quartz Event Services used in keylogging or screen monitoring.

macos:unifiedlog subsystem=com.apple.TCC macos:osquery launchd or process_events
[Service] com.apple.accessibility, com.apple.quartz, etc. depending on the API path used
[ParentProcess] Unusual parent/child pairings can indicate malicious injection
AN0285 Analytic 0285
Network Devices

Detects web-based credential phishing by analyzing traffic to suspicious URLs that mimic login portals and POST credential content.

NSM:Flow http.log NSM:Firewall proxy or TLS inspection logs
[UserAgent] Mismatched browser identifiers used by phishing kits
[URL_Path] Paths resembling known login forms but hosted on unknown domains

Detected Techniques

1

Collection (1)

Details

MITRE ID
DET0102
STIX ID
x-mitre-detection-strategy--c922d994-74bd-4847-a870-c0ae216318c9
Analytics
4
Techniques Detected
1
By Tactic
Collection
1
Leaving Threaticon

This link opens an external site that isn't part of the platform.