1200KM / detection
T0852 Screen Capture — Detection Rules
Detection workspace for T0852 Screen Capture: 0 Sigma sources, 0 Atlas concepts and 0 anomaly models. No live detection validation.
Source-backed rule directory
No reviewed association in this snapshot.
Atlas deterministic concepts
No exact concept selected.
Anomaly models
No exact Atlas model in this snapshot.
ATT&CK analytic guidance
DET0751 Detection of Screen Capture
AN1883 Analytic 1883
Monitor executed commands and arguments that may attempt to take screen captures of the desktop to gather information over the course of an operation. Monitoring for screen capture behavior will depend on the method used to obtain data from the operating system and write output files. Detection methods could include collecting information from unusual processes using API calls used to obtain image data, and monitoring for image files written to disk, such as CopyFromScreen, xwd, or screencapture. The data may need to be correlated with other events to identify malicious activity, depending on the legitimacy of this behavior within a given network environment.
Connected ecosystem references
Linked tags
Simulation, tools and telemetry
No reviewed association in this snapshot.
Existing anomaly research
Pinned research references. No browser attack runner, live simulation result or validated detector is asserted. Source mappings and validation limits are preserved. ATT&CK / Atomic provenance · Detection provenance.