T1113 — Screen Capture
T1113: Screen Capture
MITRE ATT&CK® Enterprise technique
| Tactics | Collection |
| Platforms | Linux, macOS, Windows |
| Permissions required | — |
| Version | 1.1 |
Description
Adversaries may attempt to take screen captures of the desktop to gather information over the course of an operation. Screen capturing functionality may be included as a feature of a remote access tool used in post-compromise operations. Taking a screenshot is also typically possible through native utilities or API calls, such as <code>CopyFromScreen</code>, <code>xwd</code>, or <code>screencapture</code>.(Citation: CopyFromScreen .NET)(Citation: Antiquated Mac Malware)
Detection
(no detection guidance published)
Data sources
- (none listed)
References
- ATT&CK page: https://attack.mitre.org/techniques/T1113
- ATT&CK Enterprise matrix: https://attack.mitre.org/matrices/enterprise/