1200KM / simulation
T1056.001 Keylogging — Attack Simulation
Adversaries may log user keystrokes to intercept credentials as the user types them. Keylogging is likely to be used to acquire credentials for new access opportunities when OS Credential Dumping efforts are not effective, and may require an adversary to intercept keystrokes on a system for a substantial period of time before credentials can be successfully captured. In order to increase the likelihood of capturing credentials quickly, an…
Technique description
Adversaries may log user keystrokes to intercept credentials as the user types them. Keylogging is likely to be used to acquire credentials for new access opportunities when OS Credential Dumping efforts are not effective, and may require an adversary to intercept keystrokes on a system for a substantial period of time before credentials can be successfully captured. In order to increase the likelihood of capturing credentials quickly, an…
At least one platform-compatible Atomic procedure is documented. Individual review, lab prerequisites, and validation remain required.
Official ATT&CK definition · Detection rules and anomaly models
Documented simulation candidates
- Logging bash history to syslog
Procedure 0e59d59d-3265-4d35-bebd-bf5c1ec40db5; elevation required; cleanup present, not reviewed. Not executed or individually validated.
- Bash session based keylogger
Procedure 7f85a946-a0ea-48aa-b6ac-8ff539278258; elevation not declared required; cleanup present, not reviewed. Not executed or individually validated.
- SSHD PAM keylogger
Procedure 81d7d2ad-d644-4b6a-bea7-28ffe43becca; elevation required; cleanup present, not reviewed. Not executed or individually validated.
- Living off the land Terminal Input Capture on Linux with pam.d
Procedure 9c6bdb34-a89f-4b90-acb1-5970614c711b; elevation required; cleanup present, not reviewed. Not executed or individually validated.
- Auditd keylogger
Procedure a668edb9-334e-48eb-8c2e-5413a40867af; elevation required; cleanup present, not reviewed. Not executed or individually validated.
- MacOS Swift Keylogger
Procedure aee3a097-4c5c-4fff-bbd3-0a705867ae29; elevation not declared required; cleanup present, not reviewed. Not executed or individually validated.
- Logging sh history to syslog/messages
Procedure b04284dc-3bd9-4840-8d21-61b8d31c99f2; elevation required; cleanup present, not reviewed. Not executed or individually validated.
- Input Capture
Procedure d9b633ca-8efb-45e6-b838-70f595c6ae26; elevation required; cleanup present, not reviewed. Not executed or individually validated.
Connected ecosystem references
Linked tags
Detection and collection
Attack tools
Threat actor context
These are explicit actor-to-technique associations in the existing Threat Matrix snapshot, not attribution of an event or proof that a detector identifies the actor. No tool-to-actor relationship is inferred.
- Ke3chang · G0004
- APT28 · G0007
- Darkhotel · G0012
- APT3 · G0022
- Threat Group-3390 · G0027
- Lazarus Group · G0032
- Sandworm Team · G0034
- Group5 · G0043
- menuPass · G0045
- OilRig · G0049
- APT32 · G0050
- Sowbug · G0054
- Magic Hound · G0059
- PLATINUM · G0068
- APT38 · G0082
- FIN4 · G0085
- APT39 · G0087
- Kimsuky · G0094
- APT41 · G0096
- Ajax Security Team · G0130
- Tonto Team · G0131
- HEXANE · G1001
- FIN13 · G1016
- Volt Typhoon · G1017
- APT5 · G1023
- APT42 · G1044
Existing research
Pinned research references. No browser attack runner, live simulation result or validated detector is asserted. Source mappings and validation limits are preserved. ATT&CK / Atomic provenance · Detection provenance.