kevmap

Techniques › T1056

T1056 Input Capture

collection · credential access — Linux, macOS, Network Devices, Windows · attack.mitre.org · JSON

1
MITRE detection strategy
4
analytics
2
Sigma rules tagged attack.t1056
3
KEV CVEs mapped here
<p>Adversaries may use methods of capturing user input to obtain credentials or collect information. During normal system usage, users often provide credentials to various different locations, such as login pages/portals or system dialog boxes. Input capture mechanisms may be transparent to the user (e.g. Credential API Hooking) or rely on deceiving the user into providing input into what they believe to be a genuine service (e.g. Web Portal Capture).</p>

KEV CVEs mapped to this technique · CTID Mappings Explorer

CVEVendor / productMapping typeStateAdded
CVE-2024-42009Roundcube Webmail primary impact Mapped2025-06-09
CVE-2020-8195Citrix Application Delivery Controller (ADC), Gateway, and SD-WAN WANOP Appliance exploitation technique Mapped2021-11-03
CVE-2020-8196Citrix Application Delivery Controller (ADC), Gateway, and SD-WAN WANOP Appliance exploitation technique Mapped2021-11-03

Detection strategy · ATT&CK Enterprise v19.2

Sigma rules · SigmaHQ da9bb07d64, tag attack.t1056

Author: Josh Nickels · 2024-02-26 · logsource: product=windows category=dns_query · df68f791-ad95-447f-a271-640a0dab9cf8
Detects DNS query requests to "update.onelaunch.com". This domain is associated with the OneLaunch adware application. When the OneLaunch application is installed it will attempt to get updates from this domain.
Techniques: T1056
Author: Gavin Knapp · 2023-03-16 · logsource: category=proxy · eb6c2004-1cef-427f-8885-9042974e5eb6
Detects connections to interplanetary file system (IPFS) containing a user's email address which mirrors behaviours observed in recent phishing campaigns leveraging IPFS to host credential harvesting webpages.
Techniques: T1056

Sub-techniques

IDNameSigma rulesKEV CVEs
T1056.001Keylogging31
T1056.002GUI Input Capture30
T1056.003Web Portal Capture00
T1056.004Credential API Hooking00