1200KM / tool
NPPSPY — Attack Tool
NPPSPY is an implementation of a theoretical mechanism first presented in 2004 for capturing credentials submitted to a Windows system via a rogue Network Provider API item. NPPSPY captures credentials following submission and writes them to a file on the victim system for follow-on exfiltration.
Tool identity and evidence
Included because the active pinned ATT&CK object has type tool. This is an upstream classification, not an assurance of benignness or a recommendation to run it.
Aliases: NPPSPY
Existing author guides
No reviewed association in this snapshot.
Primary documentation
No reviewed association in this snapshot.
Connected ecosystem references
Linked tags
Technique-specific simulations and detections
Detection links describe the associated behavior, not independently verified tool-specific signatures.
- T1005 · Data from Local System · Detection rules & anomalies
- T1056 · Input Capture · Detection rules & anomalies
- T1112 · Modify Registry · Detection rules & anomalies
- T1119 · Automated Collection · Detection rules & anomalies
- T1552 · Unsecured Credentials · Detection rules & anomalies
- T1557 · Adversary-in-the-Middle · Detection rules & anomalies
- T1684.001 · Impersonation · Detection rules & anomalies
Telemetry context
Derived from the explicitly linked TTPs; not proof of sensor coverage for this tool.
- Application Log Content · DC0038
- Cloud Service Metadata · DC0070
- Command Execution · DC0064
- File Access · DC0055
- File Creation · DC0039
- File Modification · DC0061
- Logon Session Creation · DC0067
- Network Connection Creation · DC0082
- Network Traffic Content · DC0085
- Network Traffic Flow · DC0078
- OS API Execution · DC0021
- Process Access · DC0035
- Process Creation · DC0032
- Process Metadata · DC0034
- Script Execution · DC0029
- User Account Authentication · DC0002
- Windows Registry Key Modification · DC0063
Pinned research references. No browser attack runner, live simulation result or validated detector is asserted. Source mappings and validation limits are preserved. ATT&CK / Atomic provenance · Detection provenance.