FORENSIA

ATT&CK · T1056

Input Capture

Tactics: collection, credential-access

About

Adversaries may use methods of capturing user input to obtain credentials or collect information. During normal system usage, users often provide credentials to various different locations, such as login pages/portals or system dialog boxes. Input capture mechanisms may be transparent to the user (e.g. Credential API Hooking) or rely on deceiving the user into providing input into what they believe to be a genuine service (e.g. Web Portal Capture).

Platforms: Linux, macOS, Network Devices, WindowsMITRE ATT&CK ↗

Used by actors

3 known groups

Software

7 malware/tools implement this

FlawedAmmyyChaesKobalosmetaMainMafaldaNPPSPYInvisibleFerret

Corpus indicators tagged with this technique

354 indicators in the corpus carry T1056.

IndicatorTypeFamilySevSrc
0b47f8d79e37ebec7edd2333ab70caa1e3e710b310b8201c5447820886ce8d49sha256phishing803
0f2aa62136bee5996123b88a8a5216ad3822252ddb110c5e66728bd49ec270desha256phishing803
415b253a81e67c8c860a97c73edc9017ce732b3c025d943d3b1a445b4ac82822sha256801
614115669d093c58539e8183617a62a59aefd1a9a1fddcc7a67508f2fb9e36absha256phishing803
f9f6314fc9f333b1aa92afdd63a98927b85fd01607e907e69b4682d18f31d2a1sha256phishing803
0542b57b67b021f877969c900214362d62eb2ba56d0645ab4e62838c8c79733asha256phishing804
8e5546c83d764e1287b55cbe868a45344a6f0afa9782d798d03b2b7cfc53ec38hashphishing801
185633e5dbe9235fc7e6a1ccb8631650afefd8f7da88c5c07d9b99ea38159822sha256801
33d887ca2e57fa03fc807dfba5376bf96718ee88f56e90d95ee4896a2c019bd0sha256801
dfa9c6adac98311d0f62e0eeecb947d92f7bda41ddf4ce9a6f9e20af7990422dsha256801
248da1553ce35bb6c499a660fcd92bde6e3545b56b65b63308e7b7630f376bfcsha256phishing803
bb551faff31c0a2c073b8a8cde34b41b6aed6e3aa7ca190e4764fdbc037be2c3sha256phishing804
49c7b4eb6620917ee7ca796472b7af9f01ea6f7f80391ae7eb7bd8dabe0b7249sha256phishing804
e14539685087d21a47968ec6f07d7e6c385b8487fd7d0fbd635918f01d2f01acsha256phishing803
daa335553542dea9666a83b3f49e85b51193a39e809fd899bfcbc2d35fcc0c3esha256phishing803
ee4f710c68bc2214febeb0127ccb5e111e1a4d01f6d4503efd22a88fb1464606sha256phishing803
4fe8bec780537aa223406965415c1f85e83eec1f4e2181cf82e2a7b7516026e6hashphishing801
0e1a306ac4b6770dbc8cb194021a9f32e9a726478db2e39084d4baa892c69521sha256phishing803
256f595afb005303a693fe26a03f9fce6d47b225bfc2300e418f5f80a89089d2sha256phishing803
ec7b0bc82c00464d8e0a59bc19c585e2hashphishing801
5aa7afd790481ad98357636fa4d9927ae01111409c8d7ce69998d2485c1d5e6fsha256801
95cda8431419f77407484ab72dc1e356421dcd801eccabe8869f77ee0eb58eb2sha256801
0081bb2de5a6599ee14cba1d0df8ff7dd63fe8b070cd18dd7b11c2adfa5e7876sha256phishing803
3d8e5092a9852b61d8d45bd3c7e2d99907fcaa9a8fd3fe3b9efcbc9255947606sha256phishing803
4f12ec57cca013dce1a5bcaf11ddf5d85fc2ecbc52afb9e61e4154d1be2d9ef3sha256phishing803
7ffd8ab8cad744263a4f16c8e96da8b8c38818b480dbeaec91e4224ac70b7ec1sha256phishing803
975cf719a576788055ca2a6b7b44aaed36c27a8676ea8d50b25a9f935eaf9d79sha256phishing803
97e74ad16c88b4b07722b5ad42dba95d837b6bdb9fa1193615f42fb34af5684fsha256phishing803
c884b1e59bad0101ecf86bd1b5b9e0e2819d5c4d1bd6eac7d76da61db06baa73sha256phishing803
1982710eb67791c9c5ac55e13abad0c24d0210c1383eedbda20855944bfe75bdsha256phishing803

Showing the top 30 by severity of 354.