{"id":"T1056","name":"Input Capture","url":"https://attack.mitre.org/techniques/T1056","tactics":["collection","credential-access"],"platforms":["Linux","macOS","Network Devices","Windows"],"live":true,"revoked":false,"deprecated":false,"revoked_by":null,"detection_strategies":[{"id":"DET0102","stix_id":"x-mitre-detection-strategy--c922d994-74bd-4847-a870-c0ae216318c9","name":"Behavioral Detection of Input Capture Across Platforms","url":"https://attack.mitre.org/detectionstrategies/DET0102","analytics":[{"id":"AN0282","stix_id":"x-mitre-analytic--dd283114-84d8-4b1a-a765-f3a7f378c2d1","name":"Analytic 0282","description":"Monitors for abnormal process behavior and API calls like SetWindowsHookEx, GetAsyncKeyState, or device input polling commonly used for keystroke logging.","url":"https://attack.mitre.org/detectionstrategies/DET0102#AN0282","platforms":["Windows"],"log_source_references":[{"name":"WinEventLog:Sysmon","channel":"EventCode=10","data_component":"DC0035","data_component_name":"Process Access","log_source_slug":"wineventlog-sysmon"},{"name":"WinEventLog:Security","channel":"EventCode=4663, 4670, 4656","data_component":"DC0055","data_component_name":"File Access","log_source_slug":"wineventlog-security"}],"mutable_elements":[{"field":"TargetImage","description":"Can be scoped to sensitive GUI processes like explorer.exe or winlogon.exe"},{"field":"TimeWindow","description":"Time threshold for detecting multiple suspicious accesses"}],"live":true,"detection_strategies":["DET0102"],"techniques":["T1056"]},{"id":"AN0283","stix_id":"x-mitre-analytic--79f3bf7a-cf35-442c-b707-ba4dabd6ed62","name":"Analytic 0283","description":"Detects use of tools/scripts accessing input devices like /dev/input/* or evdev via suspicious processes lacking GUI context.","url":"https://attack.mitre.org/detectionstrategies/DET0102#AN0283","platforms":["Linux"],"log_source_references":[{"name":"auditd:SYSCALL","channel":"open, read","data_component":"DC0055","data_component_name":"File Access","log_source_slug":"auditd-syscall"},{"name":"auditd:SYSCALL","channel":"write","data_component":"DC0061","data_component_name":"File Modification","log_source_slug":"auditd-syscall"},{"name":"auditd:SYSCALL","channel":"ptrace, ioctl","data_component":"DC0021","data_component_name":"OS API Execution","log_source_slug":"auditd-syscall"}],"mutable_elements":[{"field":"ProcessName","description":"Unusual process accessing device files"},{"field":"DevicePath","description":"Typically /dev/input/*, but tunable to exact endpoint config"}],"live":true,"detection_strategies":["DET0102"],"techniques":["T1056"]},{"id":"AN0284","stix_id":"x-mitre-analytic--13f8fd10-3982-4a10-85c1-4641712c7286","name":"Analytic 0284","description":"Monitors for TCC-bypassing or unauthorized access to input services like IOHIDSystem or Quartz Event Services used in keylogging or screen monitoring.","url":"https://attack.mitre.org/detectionstrategies/DET0102#AN0284","platforms":["macOS"],"log_source_references":[{"name":"macos:unifiedlog","channel":"subsystem=com.apple.TCC","data_component":"DC0034","data_component_name":"Process Metadata","log_source_slug":"macos-unifiedlog"},{"name":"macos:osquery","channel":"launchd or process_events","data_component":"DC0032","data_component_name":"Process Creation","log_source_slug":"macos-osquery"}],"mutable_elements":[{"field":"Service","description":"com.apple.accessibility, com.apple.quartz, etc. depending on the API path used"},{"field":"ParentProcess","description":"Unusual parent/child pairings can indicate malicious injection"}],"live":true,"detection_strategies":["DET0102"],"techniques":["T1056"]},{"id":"AN0285","stix_id":"x-mitre-analytic--6db136be-4e41-4cb7-8237-eee81ee6a3cd","name":"Analytic 0285","description":"Detects web-based credential phishing by analyzing traffic to suspicious URLs that mimic login portals and POST credential content.","url":"https://attack.mitre.org/detectionstrategies/DET0102#AN0285","platforms":["Network Devices"],"log_source_references":[{"name":"NSM:Flow","channel":"http.log","data_component":"DC0085","data_component_name":"Network Traffic Content","log_source_slug":"nsm-flow"},{"name":"NSM:Firewall","channel":"proxy or TLS inspection logs","data_component":"DC0082","data_component_name":"Network Connection Creation","log_source_slug":"nsm-firewall"}],"mutable_elements":[{"field":"UserAgent","description":"Mismatched browser identifiers used by phishing kits"},{"field":"URL_Path","description":"Paths resembling known login forms but hosted on unknown domains"}],"live":true,"detection_strategies":["DET0102"],"techniques":["T1056"]}],"live":true,"version":"1.0","techniques":["T1056"]}],"sigma_rules":[{"id":"df68f791-ad95-447f-a271-640a0dab9cf8","title":"DNS Query Request To OneLaunch Update Service","author":"Josh Nickels","status":"test","level":"low","date":"2024-02-26","modified":null,"description":"Detects DNS query requests to \"update.onelaunch.com\". This domain is associated with the OneLaunch adware application.\nWhen the OneLaunch application is installed it will attempt to get updates from this domain.\n","references":["https://www.malwarebytes.com/blog/detections/pup-optional-onelaunch-silentcf","https://www.myantispyware.com/2020/12/14/how-to-uninstall-onelaunch-browser-removal-guide/","https://malware.guide/browser-hijacker/remove-onelaunch-virus/"],"logsource":{"product":"windows","category":"dns_query"},"tags":["attack.credential-access","attack.collection","attack.t1056"],"path":"rules/windows/dns_query/dns_query_win_onelaunch_update_service.yml","techniques":["T1056"],"cves":[]},{"id":"eb6c2004-1cef-427f-8885-9042974e5eb6","title":"Suspicious Network Communication With IPFS","author":"Gavin Knapp","status":"test","level":"low","date":"2023-03-16","modified":null,"description":"Detects connections to interplanetary file system (IPFS) containing a user's email address which mirrors behaviours observed in recent phishing campaigns leveraging IPFS to host credential harvesting webpages.","references":["https://blog.talosintelligence.com/ipfs-abuse/","https://github.com/Cisco-Talos/IOCs/tree/80caca039988252fbb3f27a2e89c2f2917f582e0/2022/11","https://isc.sans.edu/diary/IPFS%20phishing%20and%20the%20need%20for%20correctly%20set%20HTTP%20security%20headers/29638"],"logsource":{"category":"proxy"},"tags":["attack.collection","attack.credential-access","attack.t1056"],"path":"rules/web/proxy_generic/proxy_susp_ipfs_cred_harvest.yml","techniques":["T1056"],"cves":[]}],"kev_cves":[{"cveID":"CVE-2024-42009","state":"mapped","mapping_types":["primary_impact"]},{"cveID":"CVE-2020-8195","state":"mapped","mapping_types":["exploitation_technique"]},{"cveID":"CVE-2020-8196","state":"mapped","mapping_types":["exploitation_technique"]}],"_built":"2026-08-23 05:47 UTC","_attack_version":"19.2","_sigma_commit":"da9bb07d642a2826e89702445d32c795209ec108"}