Screen Capture T1113
Tactic: Collection
Adversaries may attempt to take screen captures of the desktop to gather information over the course of an operation. Screen capturing functionality may be included as a feature of a remote access tool used in post-compromise operations. Taking a screenshot is also typically possible through native utilities or API calls, such as CopyFromScreen, xwd, or screencapture.
Events covered
14 catalog events are tagged with this technique by at least one rule.
| Provider | Event | Title |
|---|---|---|
| Sysmon | Event ID 1 | Process creation |
| Sysmon | Event ID 7 | Image loaded |
| Sysmon | Event ID 11 | FileCreate |
| Sysmon | Event ID 12 | RegistryEvent (Object create and delete) |
| Sysmon | Event ID 13 | RegistryEvent (Value Set) |
| Sysmon | Event ID 14 | RegistryEvent (Key and Value Rename) |
| Security-Auditing | Event ID 4688 | A new process has been created. |
| ESF | exec | Process Execution |
| ESF | write | File Write |
| Linux-Auditd | Event ID 1309 | EXECVE |
| PowerShell | Event ID 4104 | Creating Scriptblock text (MessageNumber of MessageTotal). |
| TerminalServices-RemoteConnectionManager | Event ID 20503 | Shadow View Session Started. |
| TerminalServices-RemoteConnectionManager | Event ID 20504 | Shadow View Session Stopped. |
| TerminalServices-RemoteConnectionManager | Event ID 20508 | Shadow View Permission Granted. |
Authoring guide
These 27 rules share fields, values, and exclusions.
Fields filtered most (29 distinct)
These fields appear most often in rule filters.
Top indicator values (125 distinct)
These values appear most often in rule predicates.
Exclusions (36 distinct)
These values appear most often in top-level exclusions.
Rules under this technique
These vendors publish rules tagged with this technique.
Domain: Endpoint
Sigma 13 rules
- Periodic Backup For System Registry Hives Enabled
- RDP shadow session configuration enabled (registry)
- RDP shadow session started (command)
- RDP shadow session started (native)
- Screen Capture - macOS
- Screen Capture Activity Via Psr.EXE
- Screen Capture with Import Tool
- Screen Capture with Xwd
- System Drawing DLL Load
- Windows Recall Feature Enabled - DisableAIDataAnalysis Value Deleted
- Windows Recall Feature Enabled - Registry
- Windows Recall Feature Enabled Via Reg.EXE
- Windows Screen Capture with CopyFromScreen
Elastic 5 rules
- Linux Video Recording or Screenshot Activity Detected
- Potential Remote Desktop Shadowing Activity
- PowerShell Script with Screen Capture Capability
- PowerShell Suspicious Script with Screenshot Capabilities
- Suspicious Image Creation via ScreenCapture
Splunk 8 rules
- NirCmd Execution (PowerShell)
- NirCmd Execution (Sysmon)
- NirCmd Execution (Windows Event Log)
- Remcos RAT File Creation in Remcos Folder
- Suspicious Image Creation In Appdata Folder
- Suspicious WAV file in Appdata Folder
- Windows Screen Capture in TEMP folder
- Windows Screen Capture Via Powershell