1200kmSECURITY RESEARCH
Loading interactive filters…

1200KM / detection

T1113 Screen Capture — Detection Rules

Detection workspace for T1113 Screen Capture: 9 Sigma sources, 1 Atlas concepts and 0 anomaly models. No live detection validation.

Source-backed rule directory

Atlas deterministic concepts

T1113 Screen Capture

MATCH(screen_capture_api_or_known_capture_tool) AND process NOT_IN approved_capture_apps -> ALERT

Anomaly models

No exact Atlas model in this snapshot.

ATT&CK analytic guidance

DET0346 Detect Screen Capture via Commands and API Calls

AN0980 Analytic 0980

Unusual use of screen capture APIs (e.g., CopyFromScreen) or command-line tools to write image files to disk.

AN0981 Analytic 0981

Invocation of built-in commands like screencapture or use of undocumented APIs from suspicious parent processes.

AN0982 Analytic 0982

Use of tools like xwd or import to generate screenshots, especially under non-GUI parent processes.

Connected ecosystem references

Linked tags

Simulation, tools and telemetry

T1113 simulation workspace

Threat actor context

These are explicit actor-to-technique associations in the existing Threat Matrix snapshot, not attribution of an event or proof that a detector identifies the actor. No tool-to-actor relationship is inferred.

Existing anomaly research

Original publication snapshot · Anomaly Detection Atlas

Pinned research references. No browser attack runner, live simulation result or validated detector is asserted. Source mappings and validation limits are preserved. ATT&CK / Atomic provenance · Detection provenance.