Cross-source coverage
T1113 / ATT&CK
Screen Capture
36 rules · 30 families across 6 sources.
1 deprecated hidden · include
From MITRE ATT&CK 19.2
Adversaries may attempt to take screen captures of the desktop to gather information over the course of an operation. Screen capturing functionality may be included as a feature of a remote access tool used in post-compromise operations. Taking a screenshot is also typically possible through native utilities or API calls, such as CopyFromScreen, xwd, or screencapture.
- Tactics
- Collection
- Platforms
- Linux · macOS · Windows
- Telemetry
-
WinEventLog:Sysmonmacos:unifiedlogauditd:SYSCALL
How MITRE says to detect it DET0346
Detect Screen Capture via Commands and API Calls
Windows Analytic 0980
Unusual use of screen capture APIs (e.g., CopyFromScreen) or command-line tools to write image files to disk.
WinEventLog:SysmonEventCode=1WinEventLog:SysmonEventCode=7
macOS Analytic 0981
Invocation of built-in commands like screencapture or use of undocumented APIs from suspicious parent processes.
macos:unifiedlogprocess: exec
Linux Analytic 0982
Use of tools like xwd or import to generate screenshots, especially under non-GUI parent processes.
auditd:SYSCALLexecve
socfortress/Wazuh-Rules
15 rules · 9 families| Detection | Severity | Format |
|---|---|---|
| Detects adversary creating screen capture of a desktop with Import Tool. 4 variants | High | Wazuh XML |
| Detects adversary creating screen capture of a desktop with Import Tool. 4 variants | High | Wazuh XML |
| Detects adversary creating screen capture of a desktop with Import Tool. 4 variants | High | Wazuh XML |
| Detects adversary creating screen capture of a desktop with Import Tool. 4 variants | High | Wazuh XML |
| Detects adversary creating screen capture of a full with xwd. 4 variants | High | Wazuh XML |
| Detects adversary creating screen capture of a full with xwd. 4 variants | High | Wazuh XML |
| Detects adversary creating screen capture of a full with xwd. 4 variants | High | Wazuh XML |
| Detects adversary creating screen capture of a full with xwd. 4 variants | High | Wazuh XML |
| Powershell script: Screen capture cmdlet detected | High | Wazuh XML |
| Sysmon - Event 14: RegistryEvent (Key and Value Rename) by · Recall Enabled via Registry Delete (T1113) | High | Wazuh XML |
+ 5 more from socfortress/Wazuh-Rules → showing the 10 highest-severity
SigmaHQ/sigma
10 rules| Detection | Severity | Format |
|---|---|---|
| Periodic Backup For System Registry Hives Enabled | Medium | Sigma |
| Screen Capture Activity Via Psr.EXE | Medium | Sigma |
| Windows Recall Feature Enabled - DisableAIDataAnalysis Value Deleted | Medium | Sigma |
| Windows Recall Feature Enabled - Registry | Medium | Sigma |
| Windows Recall Feature Enabled Via Reg.EXE | Medium | Sigma |
| Windows Screen Capture with CopyFromScreen | Medium | Sigma |
| Screen Capture - macOS | Low | Sigma |
| Screen Capture with Import Tool | Low | Sigma |
| Screen Capture with Xwd | Low | Sigma |
| System Drawing DLL Load | Low | Sigma |
splunk/security_content
5 rules| Detection | Severity | Format |
|---|---|---|
| Remcos RAT File Creation in Remcos Folder | Undefined | SPL |
| Suspicious Image Creation In Appdata Folder | Undefined | SPL |
| Suspicious WAV file in Appdata Folder | Undefined | SPL |
| Windows Screen Capture in TEMP folder | Undefined | SPL |
| Windows Screen Capture Via Powershell | Undefined | SPL |
elastic/detection-rules
3 rules| Detection | Severity | Format |
|---|---|---|
| Potential Remote Desktop Shadowing Activity | High | Elastic TOML |
| PowerShell Suspicious Script with Screenshot Capabilities | High | Elastic TOML |
| Linux Video Recording or Screenshot Activity Detected | Low | Elastic TOML |
elastic/protections-artifacts
2 rules| Detection | Severity | Format |
|---|---|---|
| PowerShell Script with Screen Capture Capability | Undefined | Elastic TOML |
| Suspicious Image Creation via ScreenCapture | Undefined | Elastic TOML |
Wazuh Core Ruleset
1 rule| Detection | Severity | Format |
|---|---|---|
| Screen capture method invoked from PowerShell script. | Critical | Wazuh XML |