// MITRE ATT&CK

T1056.002 · GUI Input Capture

🎯 Collection LinuxmacOSWindows Sub-technique

Sub-technique of T1056 · Input Capture.

Adversaries may mimic common operating system GUI components to prompt users for credentials with a seemingly legitimate prompt. When programs are executed that need additional privileges than are present in the current user context, it is common for the operating system to prompt the user for prope...

How to detect & mitigate it

Detecting GUI Input Capture starts with your SIEM/EDR telemetry. Write a detection rule with the Sigma generator, analyze suspicious logs in the log analyzer, and place the technique on your coverage with the ATT&CK matrix.

Related techniques

Source: MITRE ATT&CK®. ATT&CK is a registered trademark of The MITRE Corporation. Content for educational purposes.