1200KM / simulation
T1113 Screen Capture — Attack Simulation
Adversaries may attempt to take screen captures of the desktop to gather information over the course of an operation. Screen capturing functionality may be included as a feature of a remote access tool used in post-compromise operations. Taking a screenshot is also typically possible through native utilities or API calls, such as CopyFromScreen, xwd, or screencapture.
Technique description
Adversaries may attempt to take screen captures of the desktop to gather information over the course of an operation. Screen capturing functionality may be included as a feature of a remote access tool used in post-compromise operations. Taking a screenshot is also typically possible through native utilities or API calls, such as CopyFromScreen, xwd, or screencapture.
At least one platform-compatible Atomic procedure is documented. Individual review, lab prerequisites, and validation remain required.
Official ATT&CK definition · Detection rules and anomaly models
Documented simulation candidates
- Screencapture
Procedure 0f47ceb1-720f-4275-96b8-21f0562217ac; elevation not declared required; cleanup present, not reviewed. Not executed or individually validated.
- Capture Linux Desktop using Import Tool (freebsd)
Procedure 18397d87-38aa-4443-a098-8a48a8ca5d8d; elevation not declared required; cleanup present, not reviewed. Not executed or individually validated.
- Windows Screencapture
Procedure 3c898f62-626c-47d5-aad2-6de873d69153; elevation not declared required; cleanup present, not reviewed. Not executed or individually validated.
- X Windows Capture (freebsd)
Procedure 562f3bc2-74e8-46c5-95c7-0e01f9ccc65c; elevation not declared required; cleanup present, not reviewed. Not executed or individually validated.
- Windows Recall Feature Enabled - DisableAIDataAnalysis Value Deleted
Procedure 5a496325-0115-4274-8eb9-755b649ad0fb; elevation required; cleanup present, not reviewed. Not executed or individually validated.
- X Windows Capture
Procedure 8206dd0c-faf6-4d74-ba13-7fbe13dce6ac; elevation not declared required; cleanup present, not reviewed. Not executed or individually validated.
- RDP Bitmap Cache Extraction via bmc-tools
Procedure 98f19852-7348-4f99-9e15-6ff4320464c7; elevation not declared required; cleanup present, not reviewed. Not executed or individually validated.
- Capture Linux Desktop using Import Tool
Procedure 9cd1cccb-91e4-4550-9139-e20a586fcea1; elevation not declared required; cleanup present, not reviewed. Not executed or individually validated.
- Screencapture (silent)
Procedure deb7d358-5fbd-4dc4-aecc-ee0054d2d9a4; elevation not declared required; cleanup present, not reviewed. Not executed or individually validated.
- Windows Screen Capture (CopyFromScreen)
Procedure e9313014-985a-48ef-80d9-cde604ffc187; elevation not declared required; cleanup present, not reviewed. Not executed or individually validated.
Connected ecosystem references
Linked tags
Detection and collection
Attack tools
Threat actor context
These are explicit actor-to-technique associations in the existing Threat Matrix snapshot, not attribution of an event or proof that a detector identifies the actor. No tool-to-actor relationship is inferred.
- APT28 · G0007
- Dragonfly · G0035
- Group5 · G0043
- FIN7 · G0046
- Gamaredon Group · G0047
- OilRig · G0049
- Magic Hound · G0059
- BRONZE BUTLER · G0060
- MuddyWater · G0069
- Dark Caracal · G0070
- APT39 · G0087
- Silence · G0091
- Kimsuky · G0094
- GOLD SOUTHFIELD · G0115
- Volt Typhoon · G1017
- MoustachedBouncer · G1019
- Winter Vivern · G1035
- APT42 · G1044
- VOID MANTICORE · G1055
Existing research
Pinned research references. No browser attack runner, live simulation result or validated detector is asserted. Source mappings and validation limits are preserved. ATT&CK / Atomic provenance · Detection provenance.