Gold Open Source
ExplorePackagesVulnerabilitiesCWEsMCP ServersScan
Login
Gold Open Source

The authoritative source for production-ready open-source components. Every package, container image, AI model, and MCP server undergoes rigorous verification for security, malware, and license compliance.

Explore Gold

  • Explore Everything
  • Packages
  • Gold Certified Packages
  • Container Images
  • AI Models
  • MCP Servers
  • Agent Skills
  • Chip Manufacturers

Security Data & Tools

  • Scan Your Dependencies
  • Trending Threats
  • Threat RSS Feeds
  • CVE Database
  • Actively Exploited (KEV)
  • SGZ Zero-Days
  • CWE Index
  • MITRE ATT&CK
  • Malicious Packages
  • Security Glossary
  • Supply-Chain Report
  • Developers (API & Badge)
  • Chrome Extension
  • Credits & Data Sources

Products

  • The Platform
  • ESSCM
  • Portal
  • TPRM
  • OSM
  • Cowork
  • Code / Runner
  • Guard

Use Cases

  • Know Your Software
  • Auto-Fix Vulnerabilities
  • Asset Discovery
  • AI Governance
  • MCP Server Security
  • Supply Chain Compliance
  • Zero-Day Discovery
  • All Use Cases

Company

  • About
  • Pricing
  • Blog
  • Documentation
  • Safeguard Academy
  • Contact
  • Privacy Policy
  • Terms of Service

© 2026 Gold Open Source. All rights reserved.

Built with care bySafeguard
Home/ATT&CK/T1056/T1056.001
MITRE ATT&CK Sub-Technique

T1056.001: Keylogging

ShareXLinkedInRedditHN

Adversaries may log user keystrokes to intercept credentials as the user types them. Keylogging is likely to be used to acquire credentials for new access opportunities when [OS Credential Dumping](https://attack.mitre.org/techniques/T1003) efforts are not effective, and may require an adversary to intercept keystrokes on a system for a substantial period of time before credentials can be successfully captured. In order to increase the likelihood of capturing credentials quickly, an adversary may also perform actions such as clearing browser cookies to force users to reauthenticate to systems.(Citation: Talos Kimsuky Nov 2021) Keylogging is the most prevalent type of input capture, with many different ways of intercepting keystrokes.(Citation: Adventures of a Keystroke) Some methods include: * Hooking API callbacks used for processing keystrokes. Unlike [Credential API Hooking](https://attack.mitre.org/techniques/T1056/004), this focuses solely on API functions intended for processing keystroke data. * Reading raw keystroke data from the hardware buffer. * Windows Registry modifications. * Custom drivers. * [Modify System Image](https://attack.mitre.org/techniques/T1601) may provide adversaries with hooks into the operating system of network devices to read raw keystrokes for login sessions.(Citation: Cisco Blog Legacy Device Attacks)

Tactics
CollectionCredential Access
Platforms
Linux, macOS, Network Devices, Windows

▪Parent technique

T1056: Input Capture

▪Used by groups (26)

G0004Ke3changG0007APT28G0012DarkhotelG0022APT3G0027Threat Group-3390G0032Lazarus GroupG0034Sandworm TeamG0043Group5G0045menuPassG0049OilRigG0050APT32G0054SowbugG0059Magic HoundG0068PLATINUMG0082APT38G0085FIN4G0087APT39G0094KimsukyG0096APT41G0130Ajax Security TeamG0131Tonto TeamG1001HEXANEG1016FIN13G1017Volt TyphoonG1023APT5G1044APT42

▪Software using this technique (126)

S0004TinyZBotmalwareS0012PoisonIvymalwareS0013PlugXmalwareS0017BISCUITmalwareS0018SykipotmalwareS0019ReginmalwareS0021DerusbimalwareS0023CHOPSTICKmalwareS0030CarbanakmalwareS0032gh0st RATmalwareS0033NetTravelermalwareS0038DuqumalwareS0045ADVSTORESHELLmalwareS0050CosmicDukemalwareS0058SslMMmalwareS0062DustySkymalwareS0070HTTPBrowsermalwareS0072OwaAuthmalwareS0076FakeMmalwareS0088KasidetmalwareS0089BlackEnergymalwareS0090RovermalwareS0094Trojan.KaraganymalwareS0113PrikormkamalwareS0115CrimsonmalwareS0125RemsecmalwareS0128BADNEWSmalwareS0130Unknown LoggermalwareS0148RTMmalwareS0149MoonWindmalwareS0152EvilGrabmalwareS0154Cobalt StrikemalwareS0161XAgentOSXmalwareS0167MatryoshkamalwareS0170HelminthmalwareS0187DaserfmalwareS0192PupytoolS0194PowerSploittoolS0198NETWIREmalwareS0201JPINmalwareS0213DOGCALLmalwareS0234BandookmalwareS0240ROKRATmalwareS0247NavRATmalwareS0248ytymalwareS0253RunningRATmalwareS0257VERMINmalwareS0260InvisiMolemalwareS0261CatchamasmalwareS0262QuasarRATtoolS0279ProtonmalwareS0282MacSpymalwareS0283jRATmalwareS0330Zeus PandamalwareS0331Agent TeslamalwareS0332RemcostoolS0334DarkCometmalwareS0336NanoCoremalwareS0337BadPatchmalwareS0338Cobian RATmalwareS0339MicropsiamalwareS0342GreyEnergymalwareS0348Cardinal RATmalwareS0356KONNImalwareS0363EmpiretoolS0373AstarothmalwareS0375RemeximalwareS0378PoshC2toolS0379Revenge RATmalwareS0381FlawedAmmyymalwareS0385njRATmalwareS0387KeyBoymalwareS0409MachetemalwareS0410FysbismalwareS0412ZxShellmalwareS0414BabySharkmalwareS0428PoetRATmalwareS0434Imminent MonitortoolS0437KivarsmalwareS0438AttormalwareS0439OkrummalwareS0447LokibotmalwareS0454CadelspymalwareS0455MetamorfomalwareS0467TajMahalmalwareS0526KGH_SPYmalwareS0531GrandoreiromalwareS0533SLOTHFULMEDIAmalwareS0567DtrackmalwareS0569ExplosivemalwareS0593ECCENTRICBANDWAGONmalwareS0595ThiefQuestmalwareS0622AppleSeedmalwareS0625CubamalwareS0643PeppymalwareS0649SMOKEDHAMmalwareS0650QakBotmalwareS0652MarkiRATmalwareS0660ClamblingmalwareS0662RCSessionmalwareS0670WarzoneRATmalwareS0673DarkWatchmanmalwareS0692SILENTTRINITYtoolS1012PowerLessmalwareS1016MacMamalwareS1044FunnyDreammalwareS1050PcSharetoolS1059metaMainmalwareS1066DarkTortillamalwareS1087AsyncRATtoolS1090NightClubmalwareS1111DarkGatemalwareS1122MispadumalwareS1146MgBotmalwareS1149CHIMNEYSWEEPmalwareS1159DUSTTRAPmalwareS1207XLoadermalwareS1226BOOKWORMmalwareS1233PAKLOGmalwareS1235CorKLOGmalwareS1239TONESHELLmalwareS1245InvisibleFerretmalwareS1249HexEval LoadermalwareS9013DRYHOOKmalwareS9017DCRATtoolS9020LODEINFOmalware

▪Reference

T1056.001on MITRE ATT&CK

MITRE ATT&CK® is a registered trademark of The MITRE Corporation. © 2026 The MITRE Corporation. This work is reproduced and distributed with the permission of The MITRE Corporation.