Skip to content

DET0751 Detection of Screen Capture

Item Value
ID DET0751
Version 1.0
Created 21 October 2025
Last Modified 21 October 2025

Technique Detected: T0852 (Screen Capture)

Analytics

ICS

AN1883

Monitor executed commands and arguments that may attempt to take screen captures of the desktop to gather information over the course of an operation. Monitoring for screen capture behavior will depend on the method used to obtain data from the operating system and write output files. Detection methods could include collecting information from unusual processes using API calls used to obtain image data, and monitoring for image files written to disk, such as CopyFromScreen, xwd, or screencapture.(Citation: CopyFromScreen .NET)(Citation: Antiquated Mac Malware) The data may need to be correlated with other events to identify malicious activity, depending on the legitimacy of this behavior within a given network environment.

Log Sources
Data Component Name Channel
Command Execution (DC0064) Command None
OS API Execution (DC0021) Process None
Mutable Elements
Field Description