{"id":"T1056.002","name":"GUI Input Capture","url":"https://attack.mitre.org/techniques/T1056/002","tactics":["collection","credential-access"],"platforms":["Linux","macOS","Windows"],"live":true,"revoked":false,"deprecated":false,"revoked_by":null,"detection_strategies":[{"id":"DET0521","stix_id":"x-mitre-detection-strategy--909c86ca-ddd0-4e96-8464-39f5f80ef20e","name":"Behavioral Detection of Spoofed GUI Credential Prompts","url":"https://attack.mitre.org/detectionstrategies/DET0521","analytics":[{"id":"AN1440","stix_id":"x-mitre-analytic--ea127140-2f66-4c3d-93ab-215c210ad6c5","name":"Analytic 1440","description":"Detects suspicious use of PowerShell, .NET, or script interpreters to spawn processes that mimic UAC prompts, often with credential capture dialogue boxes invoked from non-standard parent processes.","url":"https://attack.mitre.org/detectionstrategies/DET0521#AN1440","platforms":["Windows"],"log_source_references":[{"name":"WinEventLog:Sysmon","channel":"EventCode=1","data_component":"DC0032","data_component_name":"Process Creation","log_source_slug":"wineventlog-sysmon"},{"name":"WinEventLog:PowerShell","channel":"EventCode=4103, 4104, 4105, 4106","data_component":"DC0064","data_component_name":"Command Execution","log_source_slug":"wineventlog-powershell"}],"mutable_elements":[{"field":"CommandLine","description":"Tunable to detect suspicious prompts like 'Enter your password' or 'CredentialRequired'"},{"field":"ParentProcessName","description":"Tune to flag UI prompts spawned from unexpected processes like cmd.exe or user scripts"},{"field":"TimeWindow","description":"Scope correlation of script execution and prompt appearance"}],"live":true,"detection_strategies":["DET0521"],"techniques":["T1056.002"]},{"id":"AN1441","stix_id":"x-mitre-analytic--c4ff3b74-bba1-4129-b246-50213e77336d","name":"Analytic 1441","description":"Detects GUI-based credential prompts invoked via zenity/kdialog/dialog or X11 APIs from non-user-facing scripts or background shell sessions, often with authentication-related text.","url":"https://attack.mitre.org/detectionstrategies/DET0521#AN1441","platforms":["Linux"],"log_source_references":[{"name":"auditd:SYSCALL","channel":"execve","data_component":"DC0032","data_component_name":"Process Creation","log_source_slug":"auditd-syscall"},{"name":"linux:cli","channel":"Terminal Command History","data_component":"DC0064","data_component_name":"Command Execution","log_source_slug":"linux-cli"}],"mutable_elements":[{"field":"ExecutableName","description":"Filter zenity/kdialog prompts launched from unexpected parent shells"},{"field":"PromptString","description":"Look for 'password', 'authentication required', or similar tokens"}],"live":true,"detection_strategies":["DET0521"],"techniques":["T1056.002"]},{"id":"AN1442","stix_id":"x-mitre-analytic--3b327a8f-0ea3-4848-b34a-58029e5edf57","name":"Analytic 1442","description":"Detects AppleScript or Objective-C usage to generate fake authentication windows (e.g., using display dialog or NSAlert) from user-launched or persistence-related processes.","url":"https://attack.mitre.org/detectionstrategies/DET0521#AN1442","platforms":["macOS"],"log_source_references":[{"name":"macos:unifiedlog","channel":"subsystem=com.apple.Security or com.apple.applescript","data_component":"DC0029","data_component_name":"Script Execution","log_source_slug":"macos-unifiedlog"},{"name":"macos:osquery","channel":"process_events","data_component":"DC0032","data_component_name":"Process Creation","log_source_slug":"macos-osquery"}],"mutable_elements":[{"field":"ScriptContent","description":"AppleScript snippets like 'display dialog' or 'with hidden answer'"},{"field":"ProcessPath","description":"Tune out Apple-signed and expected automation tasks"}],"live":true,"detection_strategies":["DET0521"],"techniques":["T1056.002"]}],"live":true,"version":"1.0","techniques":["T1056.002"]}],"sigma_rules":[{"id":"60f1ce20-484e-41bd-85f4-ac4afec2c541","title":"GUI Input Capture - macOS","author":"remotephone, oscd.community","status":"test","level":"low","date":"2020-10-13","modified":"2025-12-05","description":"Detects attempts to use system dialog prompts to capture user credentials","references":["https://github.com/redcanaryco/atomic-red-team/blob/f339e7da7d05f6057fdfcdd3742bfcf365fee2a9/atomics/T1056.002/T1056.002.md","https://scriptingosx.com/2018/08/user-interaction-from-bash-scripts/"],"logsource":{"product":"macos","category":"process_creation"},"tags":["attack.collection","attack.credential-access","attack.t1056.002"],"path":"rules/macos/process_creation/proc_creation_macos_gui_input_capture.yml","techniques":["T1056.002"],"cves":[]},{"id":"9ae01559-cf7e-4f8e-8e14-4c290a1b4784","title":"CredUI.DLL Loaded By Uncommon Process","author":"Roberto Rodriguez (Cyb3rWard0g), OTR (Open Threat Research)","status":"test","level":"medium","date":"2020-10-20","modified":"2026-06-29","description":"Detects loading of \"credui.dll\" and related DLLs by an uncommon process. Attackers might leverage this DLL for potential use of \"CredUIPromptForCredentials\" or \"CredUnPackAuthenticationBufferW\".","references":["https://securitydatasets.com/notebooks/atomic/windows/credential_access/SDWIN-201020013208.html","https://github.com/redcanaryco/atomic-red-team/blob/f339e7da7d05f6057fdfcdd3742bfcf365fee2a9/atomics/T1056.002/T1056.002.md#atomic-test-2---powershell---prompt-user-for-password","https://learn.microsoft.com/en-us/windows/win32/api/wincred/nf-wincred-creduipromptforcredentialsa","https://github.com/S12cybersecurity/RDPCredentialStealer"],"logsource":{"product":"windows","category":"image_load"},"tags":["attack.credential-access","attack.collection","attack.t1056.002"],"path":"rules/windows/image_load/image_load_dll_credui_uncommon_process_load.yml","techniques":["T1056.002"],"cves":[]},{"id":"c9192ad9-75e5-43eb-8647-82a0a5b493e3","title":"PUA - Mouse Lock Execution","author":"Cian Heasley","status":"test","level":"medium","date":"2020-08-13","modified":"2023-02-21","description":"In Kaspersky's 2020 Incident Response Analyst Report they listed legitimate tool \"Mouse Lock\" as being used for both credential access and collection in security incidents.","references":["https://github.com/klsecservices/Publications/blob/657deb6a6eb6e00669afd40173f425fb49682eaa/Incident-Response-Analyst-Report-2020.pdf","https://sourceforge.net/projects/mouselock/"],"logsource":{"product":"windows","category":"process_creation"},"tags":["attack.credential-access","attack.collection","attack.t1056.002"],"path":"rules/windows/process_creation/proc_creation_win_pua_mouselock_execution.yml","techniques":["T1056.002"],"cves":[]}],"kev_cves":[],"_built":"2026-08-24 19:45 UTC","_attack_version":"19.2","_sigma_commit":"da9bb07d642a2826e89702445d32c795209ec108"}