LiveActive security incident?Get immediate response
MITRE ATT&CK® Technique

T1056.001: Keylogging

Adversaries may log user keystrokes to intercept credentials as the user types them. Keylogging is likely to be used to acquire credentials for new access opportunities when OS Credential Dumping efforts are not effective, and may require an adversary to intercept keystrokes on a system for a substantial period of time before credentials can be successfully captured. In order to increase the likelihood of capturing credentials quickly, an adversary may also perform actions such as clearing browser cookies to force users to reauthenticate to systems.CitationTalos Kimsuky Nov 2021

Keylogging is the most prevalent type of input capture, with many different ways of intercepting keystrokes.CitationAdventures of a Keystroke Some methods include:

* Hooking API callbacks used for processing keystrokes. Unlike Credential API Hooking, this focuses solely on API functions intended for processing keystroke data. * Reading raw keystroke data from the hardware buffer. * Windows Registry modifications. * Custom drivers. * Modify System Image may provide adversaries with hooks into the operating system of network devices to read raw keystrokes for login sessions.CitationCisco Blog Legacy Device Attacks

EnterpriseT1056.001Sub-techniqueObject v1.3Modified
Glexia's Take · Automated analysis

Security context for executives and security teams

Automation confidenceHigh

Keylogging matters because it targets the moment users type secrets, especially when other credential theft methods do not work. For leaders, the practical risk is not the keystroke capture itself but the downstream access it can enable across business systems, cloud portals, VPNs, administrator consoles, and network devices. ATT&CK also notes that adversaries may wait for credentials over time or force reauthentication by clearing browser cookies, which makes this behavior relevant to SOC monitoring, identity response, and incident scoping.

Executive priority

Treat keylogging as a credential-risk and resilience issue, not only as malware. Ask whether endpoint, macOS/Linux, Windows, and network-device monitoring can show when input capture mechanisms, custom drivers, registry changes, or modified system images appear. Prioritize coverage for privileged workstations, administrator systems, remote access paths, and network devices, because captured credentials can create new access opportunities. This technique also has cyber-physical relevance where network devices or operational environments depend on administrator login sessions, as ATT&CK links keylogging to campaigns including the 2015 Ukraine Electric Power Attack.

Technical view

This is sub-technique T1056.001 under Input Capture, mapped to credential-access and collection across Linux, macOS, Network Devices, and Windows. ATT&CK describes several mechanisms: keystroke API callback hooking, raw hardware-buffer reads, Windows Registry modifications, custom drivers, and operating-system hooks in modified network-device images. No official ATT&CK detection text is provided, but relationship context identifies DET0089, Behavioral Detection of Keylogging Activity Across Platforms, as a related detection strategy. SOC and IR teams should validate whether detections are behavior-based rather than relying only on known malware names.

Likely telemetry

  • Endpoint process, module, and memory behavior associated with input capture or API callback hooking
  • Windows Registry change telemetry where keyboard/input persistence or capture behavior may be represented
  • Driver installation or load events, especially custom or unsigned/unexpected drivers
  • EDR or host audit events related to unusual access to keyboard/input data paths
  • Browser/session evidence showing unusual cookie clearing followed by forced reauthentication, where available

Detection direction

  • Start from behavioral analytics aligned to DET0089 rather than signature-only coverage.
  • Validate coverage on all ATT&CK-listed platforms actually present in the environment: Linux, macOS, Windows, and Network Devices.
  • Tune detections around unauthorized input capture behavior, unexpected hooks, driver activity, registry modification, and modified system image indicators.
  • Correlate suspected keylogging with identity events such as fresh logins, MFA prompts, reauthentication, and new access opportunities.
  • Account for legitimate software that may interact with keyboard input, such as accessibility, remote administration, or endpoint management tools, to reduce false positives.

Mitigation priorities

  • Prioritize hardening and monitoring of privileged endpoints and administrator access paths.
  • Maintain strong endpoint controls capable of observing suspicious drivers, hooks, registry changes, and input-capture behavior.
  • Use identity controls that reduce the value of captured passwords, such as strong MFA and rapid credential rotation during incidents, while recognizing ATT&CK does not state these prevent keylogging itself.
  • Protect network devices through system image integrity practices, controlled administration, and monitoring for unexpected image or configuration changes.
  • During incident response, assume credentials typed on a suspected keylogged system may be exposed and scope identity activity accordingly.
Additional notes and limits

ATT&CK associates this technique with many campaigns and groups, indicating broad historical use across espionage, financial, and disruptive contexts. That relationship context should inform threat modeling, but it should not be treated as proof of current activity in any specific environment. The strongest local assessment will come from correlating host behavior, identity logs, and network-device integrity evidence.

The official ATT&CK object provides no detection guidance text, so detection recommendations here are derived from the described behaviors, platforms, tactics, and the DET0089 relationship. Local tooling, operating system coverage, and logging quality determine whether these behaviors are observable. No claim is made that any organization is exposed or that coverage is guaranteed.

Generated from the cited source records. This long-tail analysis has not been individually reviewed by a named human.

Official MITRE ATT&CK definition

Keylogging

Adversaries may log user keystrokes to intercept credentials as the user types them. Keylogging is likely to be used to acquire credentials for new access opportunities when OS Credential Dumping efforts are not effective, and may require an adversary to intercept keystrokes on a system for a substantial period of time before credentials can be successfully captured. In order to increase the likelihood of capturing credentials quickly, an adversary may also perform actions such as clearing browser cookies to force users to reauthenticate to systems.CitationTalos Kimsuky Nov 2021

Keylogging is the most prevalent type of input capture, with many different ways of intercepting keystrokes.CitationAdventures of a Keystroke Some methods include:

* Hooking API callbacks used for processing keystrokes. Unlike Credential API Hooking, this focuses solely on API functions intended for processing keystroke data. * Reading raw keystroke data from the hardware buffer. * Windows Registry modifications. * Custom drivers. * Modify System Image may provide adversaries with hooks into the operating system of network devices to read raw keystrokes for login sessions.CitationCisco Blog Legacy Device Attacks

View the same entry on attack.mitre.org (MITRE-hosted reference; in-page links above use the Glexia ATT&CK library.)

Glexia analysis

How security teams should use this page

Treat this object as behavior context, not an attribution claim. Validate the related groups, software, data sources, and mitigations against official ATT&CK relationships and your own telemetry before making control-coverage decisions.

Relationship explorer

All related ATT&CK context

No relationships are available in the current normalized data for this object.

Change history

Object version and sync metadata

The fields below describe the current mirrored snapshot. When Glexia retains multiple ATT&CK source imports, you can open the table to compare the same object across releases (hashes and MITRE timestamps). For MITRE’s own release notes and roadmap, see ATT&CK resources — Updates.

ATT&CK release
19.1
Object version
1.3
Created
Modified
Raw hash
5b9ad065df7a1e50...
Raw source

Mirrored ATT&CK source object

The raw object is retained through the mirrored ATT&CK source bundle and object hash. The raw endpoint returns the exact object from the mirrored bundle when available.

Source and licensing

Source: MITRE ATT&CK®. © 2026 The MITRE Corporation. This work is reproduced and distributed with the permission of The MITRE Corporation. MITRE ATT&CK and ATT&CK are registered trademarks of The MITRE Corporation. Glexia is not affiliated with or endorsed by MITRE.