FORENSIA

ATT&CK · T1056.001 · sub-technique

Keylogging

Tactics: collection, credential-access

About

Adversaries may log user keystrokes to intercept credentials as the user types them. Keylogging is likely to be used to acquire credentials for new access opportunities when OS Credential Dumping efforts are not effective, and may require an adversary to intercept keystrokes on a system for a substantial period of time before credentials can be successfully captured. In order to increase the likelihood of capturing credentials quickly, an adversary may also perform actions such as clearing browser cookies to force users to reauthenticate to systems. Keylogging is the most prevalent type of input capture, with many different ways of intercepting keystrokes. Some methods include: * Hooking API callbacks used for processing keystrokes. Unlike Credential API Hooking, this focuses solely on API functions intended for processing keystroke data. * Reading raw keystroke data from the hardware buffer. * Windows Registry modifications. * Custom drivers. * Modify System Image may provide adversaries with hooks into the operating system of network devices to read raw keystrokes for login sessions.

Platforms: Linux, macOS, Network Devices, WindowsParent: T1056 Input CaptureMITRE ATT&CK ↗

Used by actors

26 known groups

Software

126 malware/tools implement this

TinyZBotPoisonIvyPlugXBISCUITSykipotReginDerusbiCHOPSTICKCarbanakgh0st RATNetTravelerDuquADVSTORESHELLCosmicDukeSslMMDustySkyHTTPBrowserOwaAuthFakeMKasidetBlackEnergyRoverTrojan.KaraganyPrikormkaCrimsonRemsecBADNEWSUnknown LoggerRTMMoonWindEvilGrabCobalt StrikeXAgentOSXMatryoshkaHelminthDaserfPupyPowerSploitNETWIREJPINDOGCALLBandookROKRATNavRATytyRunningRATVERMINInvisiMoleCatchamasQuasarRATProtonMacSpyjRATZeus PandaAgent TeslaRemcosDarkCometNanoCoreBadPatchCobian RATMicropsiaGreyEnergyCardinal RATKONNIEmpireAstarothRemexiPoshC2Revenge RATFlawedAmmyynjRATKeyBoyMacheteFysbisZxShellBabySharkPoetRATImminent MonitorKivarsAttorOkrumLokibotCadelspyMetamorfoTajMahalKGH_SPYGrandoreiroSLOTHFULMEDIADtrackExplosiveECCENTRICBANDWAGONThiefQuestAppleSeedCubaPeppySMOKEDHAMQakBotMarkiRATClamblingRCSessionWarzoneRATDarkWatchmanSILENTTRINITYPowerLessMacMaFunnyDreamPcSharemetaMainDarkTortillaAsyncRATNightClubDarkGateMispaduMgBotCHIMNEYSWEEPDUSTTRAPXLoaderBOOKWORMPAKLOGCorKLOGTONESHELLInvisibleFerretHexEval LoaderDRYHOOKDCRATLODEINFO

Corpus indicators tagged with this technique

611 indicators in the corpus carry T1056.001.

IndicatorTypeFamilySevSrc
cve-2025-2492cve852
cve-2020-22658cve852
cve-2020-22653cve852
cve-2026-3102cve853
8c9b6542f73c5c7fe455b52f5101314407da4f65ff48e7ebf6896605e607c8d0hash803
a648db354820ea4d02940cb1702b35974513b7aae83f6dffaacaac4ba31f9295hash803
78945c844fc23dd3446cf17987edeeb6cc21986820c92df82a126af24a5a38d1hash802
0d681bd160db1b1df5db321a6d2dd9ae81b2609bhash801
0ffb16209def5500ff4380d9e8093437hash803
2d2a251a88632f010fd9671789746908eeccaa5bc5c0a5d25e4649efe4f5b15dhash803
584a9448dda46bd590d7a2f86228100d2ae6e0d6d990c1a4459ed5ee28e07ae8hash803
66a3836b9a17771bce2161f6b73cbc2494a91e49d6aa30d2d53711e8d10de60dhash803
40b41979b317406f8abc601677a3b93aaf6ef8ab8ac188b8f383735e388f13b5hash803
9d0a55c545c4147956db2c2667c4ed931a2875309147548b1dfdd216228f5f73hash803
3e7066e44132e64360a30974b6ea3671hash803
606966a9ec33765baedf63331595d1168f2a596fhash803
d89bb4b23a67814ef511e4e9dda7ad36fa519a322fa7c25ea451c7dd7ef61e54hash802
f8cbe44fde6914bc8d06426c03c92ed536c891470292e567a586b54af29c2442hash802
ad10ff9043d6f327045943635fcbd0c5918acb79dc998db92ee4c7dee5224710sha256801
4c9f271242f61f1a31b8146305e9a7ed512c521445d4f7a7a901e301307add3dsha256801
64c7dd0a3a3ae49977ac05913d3878000cce14e5d8c1ee05b782bdfd648bde91sha256801
f6e4b09ef788adef3f65fd2b99da8f5be5391be29471676dc07040a56c8fdfabhash802
0857148fb0bc4aa7adf967ede2307bdb4fc427065d5b6a6db132688a5a8e1eb8hash803
3119cf37b8267db8a2dcd11d9a83d5237d7ef1e42388e7c9afa2831b91da8a2dhash803
5864a697bd7b339f56b05405f29a097cd027cafdcc4e63c2aaeccccbf930605fsha256801
7b2c661cfb69e9c75df90d5102647bb014c28ad5hash803
7b7981c99d59595fe15377df84695bb72ce0b85560a3935f930657b2d162e5efsha256phishing801
d7d2f0ee187549f3f4a114d716be12521fbf62d6d26e2ac23d2a32d521d08fd8sha256phishing801
adcd15f3d6b87f84d106ea426fa824fd20c9d64f6d199ce92580884290785f30sha256phishing801
c099f965144bccd0b590f946659fc3c0747c54aef505b6caaca9078712f455fbsha256801

Showing the top 30 by severity of 611.