{"id":"T1113","name":"Screen Capture","url":"https://attack.mitre.org/techniques/T1113","tactics":["collection"],"platforms":["Linux","macOS","Windows"],"live":true,"revoked":false,"deprecated":false,"revoked_by":null,"detection_strategies":[{"id":"DET0346","stix_id":"x-mitre-detection-strategy--a9de0990-69e9-4b1a-9754-1c7fb4102ac9","name":"Detect Screen Capture via Commands and API Calls","url":"https://attack.mitre.org/detectionstrategies/DET0346","analytics":[{"id":"AN0980","stix_id":"x-mitre-analytic--20e00aff-6389-4c8a-8e38-3b63924e1612","name":"Analytic 0980","description":"Unusual use of screen capture APIs (e.g., CopyFromScreen) or command-line tools to write image files to disk.","url":"https://attack.mitre.org/detectionstrategies/DET0346#AN0980","platforms":["Windows"],"log_source_references":[{"name":"WinEventLog:Sysmon","channel":"EventCode=1","data_component":"DC0032","data_component_name":"Process Creation","log_source_slug":"wineventlog-sysmon"},{"name":"WinEventLog:Sysmon","channel":"EventCode=7","data_component":"DC0016","data_component_name":"Module Load","log_source_slug":"wineventlog-sysmon"}],"mutable_elements":[{"field":"ParentProcessName","description":"Depends on allowed parent process behaviors in the environment (e.g., explorer.exe vs powershell.exe)"},{"field":"TimeWindow","description":"Can tune alert thresholds for rapid or scheduled screenshots (e.g., interval-based screen capture)"},{"field":"ImageExtension","description":"To detect file writes (e.g., .bmp, .png) that deviate from typical user activity"}],"live":true,"detection_strategies":["DET0346"],"techniques":["T1113"]},{"id":"AN0981","stix_id":"x-mitre-analytic--5f1a4795-74e5-49b9-85bb-e186ca699648","name":"Analytic 0981","description":"Invocation of built-in commands like screencapture or use of undocumented APIs from suspicious parent processes.","url":"https://attack.mitre.org/detectionstrategies/DET0346#AN0981","platforms":["macOS"],"log_source_references":[{"name":"macos:unifiedlog","channel":"process: exec","data_component":"DC0032","data_component_name":"Process Creation","log_source_slug":"macos-unifiedlog"}],"mutable_elements":[{"field":"CommandLineRegex","description":"Customize regex for flag detection (e.g., `screencapture -x`) based on usage patterns"},{"field":"ParentProcessName","description":"May vary depending on expected screencapture behavior (Terminal vs remote agent)"}],"live":true,"detection_strategies":["DET0346"],"techniques":["T1113"]},{"id":"AN0982","stix_id":"x-mitre-analytic--121a5310-3157-47b1-925e-998767c0ec06","name":"Analytic 0982","description":"Use of tools like xwd or import to generate screenshots, especially under non-GUI parent processes.","url":"https://attack.mitre.org/detectionstrategies/DET0346#AN0982","platforms":["Linux"],"log_source_references":[{"name":"auditd:SYSCALL","channel":"execve","data_component":"DC0032","data_component_name":"Process Creation","log_source_slug":"auditd-syscall"}],"mutable_elements":[{"field":"TerminalSession","description":"Filter based on TTY sessions or remote terminal usage"},{"field":"ExecutablePath","description":"Match against known location of xwd/import binaries or renamed variants"}],"live":true,"detection_strategies":["DET0346"],"techniques":["T1113"]}],"live":true,"version":"1.0","techniques":["T1113"]}],"sigma_rules":[{"id":"0877ed01-da46-4c49-8476-d49cdd80dfa7","title":"Screen Capture - macOS","author":"remotephone, oscd.community","status":"test","level":"low","date":"2020-10-13","modified":"2021-11-27","description":"Detects attempts to use screencapture to collect macOS screenshots","references":["https://github.com/redcanaryco/atomic-red-team/blob/f339e7da7d05f6057fdfcdd3742bfcf365fee2a9/atomics/T1113/T1113.md","https://github.com/EmpireProject/Empire/blob/08cbd274bef78243d7a8ed6443b8364acd1fc48b/lib/modules/python/collection/osx/screenshot.py"],"logsource":{"product":"macos","category":"process_creation"},"tags":["attack.collection","attack.t1113"],"path":"rules/macos/process_creation/proc_creation_macos_screencapture.yml","techniques":["T1113"],"cves":[]},{"id":"2158f96f-43c2-43cb-952a-ab4580f32382","title":"Screen Capture Activity Via Psr.EXE","author":"Beyu Denis, oscd.community","status":"test","level":"medium","date":"2019-10-12","modified":"2024-01-04","description":"Detects execution of Windows Problem Steps Recorder (psr.exe), a utility used to record the user screen and clicks.","references":["https://lolbas-project.github.io/lolbas/Binaries/Psr/","https://web.archive.org/web/20200229201156/https://www.sans.org/cyber-security-summit/archives/file/summit-archive-1493861893.pdf","https://github.com/redcanaryco/atomic-red-team/blob/f339e7da7d05f6057fdfcdd3742bfcf365fee2a9/atomics/T1560.001/T1560.001.md"],"logsource":{"product":"windows","category":"process_creation"},"tags":["attack.collection","attack.t1113"],"path":"rules/windows/process_creation/proc_creation_win_psr_capture_screenshots.yml","techniques":["T1113"],"cves":[]},{"id":"5dfc1465-8f65-4fde-8eb5-6194380c6a62","title":"Windows Recall Feature Enabled - DisableAIDataAnalysis Value Deleted","author":"Sajid Nawaz Khan","status":"test","level":"medium","date":"2024-06-02","modified":null,"description":"Detects the enabling of the Windows Recall feature via registry manipulation. Windows Recall can be enabled by deleting the existing \"DisableAIDataAnalysis\" registry value.\nAdversaries may enable Windows Recall as part of post-exploitation discovery and collection activities.\nThis rule assumes that Recall is already explicitly disabled on the host, and subsequently enabled by the adversary.\n","references":["https://learn.microsoft.com/en-us/windows/client-management/manage-recall","https://learn.microsoft.com/en-us/windows/client-management/mdm/policy-csp-windowsai#disableaidataanalysis"],"logsource":{"product":"windows","category":"registry_delete"},"tags":["attack.collection","attack.t1113"],"path":"rules/windows/registry/registry_delete/registry_delete_enable_windows_recall.yml","techniques":["T1113"],"cves":[]},{"id":"666ecfc7-229d-42b8-821e-1a8f8cb7057c","title":"System Drawing DLL Load","author":"Roberto Rodriguez (Cyb3rWard0g), OTR (Open Threat Research)","status":"test","level":"low","date":"2020-05-02","modified":"2023-02-22","description":"Detects processes loading \"System.Drawing.ni.dll\". This could be an indicator of potential Screen Capture.","references":["https://github.com/OTRF/detection-hackathon-apt29/issues/16","https://github.com/OTRF/ThreatHunter-Playbook/blob/2d4257f630f4c9770f78d0c1df059f891ffc3fec/docs/evals/apt29/detections/7.A.1_3B4E5808-3C71-406A-B181-17B0CE3178C9.md"],"logsource":{"product":"windows","category":"image_load"},"tags":["attack.collection","attack.t1113","detection.threat-hunting"],"path":"rules-threat-hunting/windows/image_load/image_load_dll_system_drawing_load.yml","techniques":["T1113"],"cves":[]},{"id":"75180c5f-4ea1-461a-a4f6-6e4700c065d4","title":"Windows Recall Feature Enabled - Registry","author":"Sajid Nawaz Khan","status":"test","level":"medium","date":"2024-06-02","modified":null,"description":"Detects the enabling of the Windows Recall feature via registry manipulation. Windows Recall can be enabled by setting the value of \"DisableAIDataAnalysis\" to \"0\".\nAdversaries may enable Windows Recall as part of post-exploitation discovery and collection activities.\nThis rule assumes that Recall is already explicitly disabled on the host, and subsequently enabled by the adversary.\n","references":["https://learn.microsoft.com/en-us/windows/client-management/manage-recall","https://learn.microsoft.com/en-us/windows/client-management/mdm/policy-csp-windowsai#disableaidataanalysis"],"logsource":{"product":"windows","category":"registry_set"},"tags":["attack.collection","attack.t1113"],"path":"rules/windows/registry/registry_set/registry_set_enable_windows_recall.yml","techniques":["T1113"],"cves":[]},{"id":"817f252c-5143-4dae-b418-48c3e9f63728","title":"Windows Recall Feature Enabled Via Reg.EXE","author":"Sajid Nawaz Khan","status":"test","level":"medium","date":"2024-06-02","modified":null,"description":"Detects the enabling of the Windows Recall feature via registry manipulation.\nWindows Recall can be enabled by deleting the existing \"DisableAIDataAnalysis\" value, or setting it to 0.\nAdversaries may enable Windows Recall as part of post-exploitation discovery and collection activities.\nThis rule assumes that Recall is already explicitly disabled on the host, and subsequently enabled by the adversary.\n","references":["https://learn.microsoft.com/en-us/windows/client-management/manage-recall","https://learn.microsoft.com/en-us/windows/client-management/mdm/policy-csp-windowsai#disableaidataanalysis"],"logsource":{"product":"windows","category":"process_creation"},"tags":["attack.collection","attack.t1113"],"path":"rules/windows/process_creation/proc_creation_win_reg_enable_windows_recall.yml","techniques":["T1113"],"cves":[]},{"id":"973ef012-8f1a-4c40-93b4-7e659a5cd17f","title":"Periodic Backup For System Registry Hives Enabled","author":"Nasreddine Bencherchali (Nextron Systems)","status":"test","level":"medium","date":"2024-07-01","modified":null,"description":"Detects the enabling of the \"EnablePeriodicBackup\" registry value. Once enabled, The OS will backup System registry hives on restarts to the \"C:\\Windows\\System32\\config\\RegBack\" folder. Windows creates a \"RegIdleBackup\" task to manage subsequent backups.\nRegistry backup was a default behavior on Windows and was disabled as of \"Windows 10, version 1803\".\n","references":["https://learn.microsoft.com/en-us/troubleshoot/windows-client/installing-updates-features-roles/system-registry-no-backed-up-regback-folder"],"logsource":{"product":"windows","category":"registry_set"},"tags":["attack.collection","attack.t1113"],"path":"rules/windows/registry/registry_set/registry_set_enable_periodic_backup.yml","techniques":["T1113"],"cves":[]},{"id":"d4a11f63-2390-411c-9adf-d791fd152830","title":"Windows Screen Capture with CopyFromScreen","author":"frack113","status":"test","level":"medium","date":"2021-12-28","modified":"2022-07-07","description":"Adversaries may attempt to take screen captures of the desktop to gather information over the course of an operation.\nScreen capturing functionality may be included as a feature of a remote access tool used in post-compromise operations\n","references":["https://github.com/redcanaryco/atomic-red-team/blob/f339e7da7d05f6057fdfcdd3742bfcf365fee2a9/atomics/T1113/T1113.md#atomic-test-6---windows-screen-capture-copyfromscreen"],"logsource":{"product":"windows","category":"ps_script"},"tags":["attack.collection","attack.t1113"],"path":"rules/windows/powershell/powershell_script/posh_ps_capture_screenshots.yml","techniques":["T1113"],"cves":[]},{"id":"dbe4b9c5-c254-4258-9688-d6af0b7967fd","title":"Screen Capture with Import Tool","author":"Pawel Mazur","status":"test","level":"low","date":"2021-09-21","modified":"2022-10-09","description":"Detects adversary creating screen capture of a desktop with Import Tool.\nHighly recommended using rule on servers, due to high usage of screenshot utilities on user workstations.\nImageMagick must be installed.\n","references":["https://github.com/redcanaryco/atomic-red-team/blob/f339e7da7d05f6057fdfcdd3742bfcf365fee2a9/atomics/T1113/T1113.md","https://linux.die.net/man/1/import","https://imagemagick.org/"],"logsource":{"product":"linux","service":"auditd"},"tags":["attack.collection","attack.t1113"],"path":"rules/linux/auditd/execve/lnx_auditd_screencapture_import.yml","techniques":["T1113"],"cves":[]},{"id":"e2f17c5d-b02a-442b-9052-6eb89c9fec9c","title":"Screen Capture with Xwd","author":"Pawel Mazur","status":"test","level":"low","date":"2021-09-13","modified":"2022-12-18","description":"Detects adversary creating screen capture of a full with xwd. Highly recommended using rule on servers, due high usage of screenshot utilities on user workstations","references":["https://github.com/redcanaryco/atomic-red-team/blob/f339e7da7d05f6057fdfcdd3742bfcf365fee2a9/atomics/T1113/T1113.md#atomic-test-3---x-windows-capture","https://linux.die.net/man/1/xwd"],"logsource":{"product":"linux","service":"auditd"},"tags":["attack.collection","attack.t1113"],"path":"rules/linux/auditd/execve/lnx_auditd_screencaputre_xwd.yml","techniques":["T1113"],"cves":[]}],"kev_cves":[],"_built":"2026-08-23 05:47 UTC","_attack_version":"19.2","_sigma_commit":"da9bb07d642a2826e89702445d32c795209ec108"}