1200kmSECURITY RESEARCH
Loading interactive filters…

1200KM / detection

T0852 Screen Capture — Detection Rules

Detection workspace for T0852 Screen Capture: 0 Sigma sources, 0 Atlas concepts and 0 anomaly models. No live detection validation.

Source-backed rule directory

No reviewed association in this snapshot.

Atlas deterministic concepts

No exact concept selected.

Anomaly models

No exact Atlas model in this snapshot.

ATT&CK analytic guidance

DET0751 Detection of Screen Capture

AN1883 Analytic 1883

Monitor executed commands and arguments that may attempt to take screen captures of the desktop to gather information over the course of an operation. Monitoring for screen capture behavior will depend on the method used to obtain data from the operating system and write output files. Detection methods could include collecting information from unusual processes using API calls used to obtain image data, and monitoring for image files written to disk, such as CopyFromScreen, xwd, or screencapture. The data may need to be correlated with other events to identify malicious activity, depending on the legitimacy of this behavior within a given network environment.

Connected ecosystem references

Linked tags

Simulation, tools and telemetry

T0852 simulation workspace

No reviewed association in this snapshot.

Existing anomaly research

Original publication snapshot · Anomaly Detection Atlas

Pinned research references. No browser attack runner, live simulation result or validated detector is asserted. Source mappings and validation limits are preserved. ATT&CK / Atomic provenance · Detection provenance.