Clankerusecase
MITRE ATT&CK detection coverage
← Back to main site
Home/ MITRE Matrix/ Collection/ T1056.002

T1056.002GUI Input Capture

T1056.002 — GUI Input Capture is a MITRE ATT&CK technique in the Collection tactic. Clankerusecase tracks 4 detection use cases covering it and 3 threat-intel articles citing it.

CollectionCredential Access
View on the matrix → Filter Detection Library MITRE official spec ↗
4Use cases
3Articles
0Sub-techniques
2Tactics

Use cases covering this technique (4)

Windows Input Capture Using Credential UI Dll ESCU actions · hunting P [LLM] AmnesiaStealer credential harvest: keychain dump, APFS TCC-bypass mount, and fake password prompt Bespoke actions · hunting DSΣPCS [LLM] macOS captured-password validation via dscl authonly + keychain unlock with cleartext password Bespoke actions · hunting DSΣPCS [LLM] Discord client tampering via index.js overwrite in discord_desktop_core (Discord Injector) Bespoke install · alerting DSΣPDDCS

Articles citing this technique (3)