Techniques › T1123
T1123 Audio Capture
collection — Linux, macOS, Windows · attack.mitre.org · JSON
1
MITRE detection strategy
3
analytics
6
Sigma rules tagged attack.t1123
0
KEV CVEs mapped here
<p>An adversary can leverage a computer's peripheral devices (e.g., microphones and webcams) or applications (e.g., voice and video call services) to capture audio recordings for the purpose of listening into sensitive conversations to gather information.</p><p>Malware or scripts may be used to interact with the devices through an available API provided by the operating system or an application to capture audio. Audio files may be written to disk and exfiltrated later.</p>
KEV CVEs mapped to this technique · CTID Mappings Explorer
None. No KEV entry in the public mapping names this technique. Given that 74.7% of KEV has no mapping at all, this says more about the mapping than about the technique.
Detection strategy · ATT&CK Enterprise v19.2
- DET0221 Behavioral Detection Strategy for T1123 Audio Capture Across Windows, Linux, macOS v1.0
AN0619 WindowsUnusual or unauthorized processes accessing microphone APIs (e.g., winmm.dll, avrt.dll) followed by audio file writes to user-accessible or temp directories.Tunable:
TimeWindowTargetProcessWriteDirectoryAN0620 LinuxProcesses accessing ALSA/PulseAudio devices or executing audio capture binaries like 'arecord', followed by file creation or suspicious child process spawning.Tunable:ExecutableNameDevicePathUserContextAN0621 macOSProcesses invoking AVFoundation or CoreAudio frameworks, accessing input devices via TCC logs or Unified Logs, followed by writing AIFF/WAV/MP3 files to disk.Tunable:FrameworkCallTargetDirectoryAnomalousParent
Sigma rules · SigmaHQ da9bb07d64, tag attack.t1123
Author: Den Iuzvyk
· 2020-06-07 (modified 2022-10-09) · logsource: product=windows category=registry_event · 62120148-6b7a-42be-8b91-271c04e281a3
Detects Processes accessing the camera and microphone from suspicious folder
Author: E.M. Anhaus (originally from Atomic Blue Detections, Endgame), oscd.community
· 2019-10-24 (modified 2021-11-27) · logsource: product=windows category=process_creation · 83865853-59aa-449e-9600-74b9d89a6d6e
Detect attacker collecting audio via SoundRecorder application.
Author: Roberto Rodriguez (Cyb3rWard0g), OTR (Open Threat Research)
· 2020-06-07 (modified 2021-11-27) · logsource: product=windows service=security · 8cd538a4-62d5-4e83-810b-12d41e428d6e
Potential adversaries accessing the microphone and webcam in an endpoint.
Author: E.M. Anhaus (originally from Atomic Blue Detections, Endgame), oscd.community, Nasreddine Bencherchali (Nextron Systems)
· 2019-10-24 (modified 2023-04-06) · logsource: product=windows category=process_creation · 932fb0d8-692b-4b0f-a26e-5643a50fe7d6
Detects audio capture via PowerShell Cmdlet.
Author: Pawel Mazur, Milad Cheraghi
· 2021-09-04 (modified 2025-12-05) · logsource: product=linux service=auditd · a7af2487-9c2f-42e4-9bb9-ff961f0561d5
Detects attempts to record audio using the arecord and ecasound utilities.
Author: Security Onion Solutions
· 2024-03-08 · logsource: product=opencanary category=application · e30de276-68ec-435c-ab99-ef3befec6c61
Detects instances where an SIP service on an OpenCanary node has had a SIP request.