1200KM / detection
T1113 Screen Capture — Detection Rules
Detection workspace for T1113 Screen Capture: 9 Sigma sources, 1 Atlas concepts and 0 anomaly models. No live detection validation.
Source-backed rule directory
- Screen Capture with Import Tool · test · low · {"product":"linux","service":"auditd"}
- Screen Capture with Xwd · test · low · {"product":"linux","service":"auditd"}
- Screen Capture - macOS · test · low · {"product":"macos","category":"process_creation"}
- Windows Screen Capture with CopyFromScreen · test · medium · {"product":"windows","category":"ps_script","definition":"Requirements: Script Block Logging must be enabled"}
- Screen Capture Activity Via Psr.EXE · test · medium · {"category":"process_creation","product":"windows"}
- Windows Recall Feature Enabled Via Reg.EXE · test · medium · {"category":"process_creation","product":"windows"}
- Windows Recall Feature Enabled - DisableAIDataAnalysis Value Deleted · test · medium · {"category":"registry_delete","product":"windows"}
- Periodic Backup For System Registry Hives Enabled · test · medium · {"category":"registry_set","product":"windows"}
- Windows Recall Feature Enabled - Registry · test · medium · {"category":"registry_set","product":"windows"}
Atlas deterministic concepts
T1113 Screen Capture
MATCH(screen_capture_api_or_known_capture_tool) AND process NOT_IN approved_capture_apps -> ALERTAnomaly models
No exact Atlas model in this snapshot.
ATT&CK analytic guidance
DET0346 Detect Screen Capture via Commands and API Calls
AN0980 Analytic 0980
Unusual use of screen capture APIs (e.g., CopyFromScreen) or command-line tools to write image files to disk.
AN0981 Analytic 0981
Invocation of built-in commands like screencapture or use of undocumented APIs from suspicious parent processes.
AN0982 Analytic 0982
Use of tools like xwd or import to generate screenshots, especially under non-GUI parent processes.
Connected ecosystem references
Linked tags
Simulation, tools and telemetry
Threat actor context
These are explicit actor-to-technique associations in the existing Threat Matrix snapshot, not attribution of an event or proof that a detector identifies the actor. No tool-to-actor relationship is inferred.
- APT28 · G0007
- Dragonfly · G0035
- Group5 · G0043
- FIN7 · G0046
- Gamaredon Group · G0047
- OilRig · G0049
- Magic Hound · G0059
- BRONZE BUTLER · G0060
- MuddyWater · G0069
- Dark Caracal · G0070
- APT39 · G0087
- Silence · G0091
- Kimsuky · G0094
- GOLD SOUTHFIELD · G0115
- Volt Typhoon · G1017
- MoustachedBouncer · G1019
- Winter Vivern · G1035
- APT42 · G1044
- VOID MANTICORE · G1055
Existing anomaly research
Pinned research references. No browser attack runner, live simulation result or validated detector is asserted. Source mappings and validation limits are preserved. ATT&CK / Atomic provenance · Detection provenance.