Applied Cybernetics Group
T1113 — Screen Capture
- Technique
T1113- Tactics
- Collection
- MISP citations
- 0
- KEV CVEs mapped
- 0
- Community rules
- 10
- thrunt rules
- 0
- Active families
- Remcos
- Upstream
- https://attack.mitre.org/techniques/T1113
MITRE description
Adversaries may attempt to take screen captures of the desktop to gather information over the course of an operation. Screen capturing functionality may be included as a feature of a remote access tool used in post-compromise operations. Taking a screenshot is also typically possible through native utilities or API calls, such as <code>CopyFromScreen</code>, <code>xwd</code>, or <code>screencapture</code>.(Citation: CopyFromScreen .NET)(Citation: Antiquated Mac Malware)
Detection coverage
SigmaHQ community rules
- System Drawing DLL Load (threat-hunting)
- Screen Capture with Import Tool (core)
- Screen Capture with Xwd (core)
- Screen Capture - macOS (core)
- Windows Screen Capture with CopyFromScreen (core)
- Screen Capture Activity Via Psr.EXE (core)
- Windows Recall Feature Enabled Via Reg.EXE (core)
- Windows Recall Feature Enabled - DisableAIDataAnalysis Value Deleted (core)
- Periodic Backup For System Registry Hives Enabled (core)
- Windows Recall Feature Enabled - Registry (core)