MITRE ATT&CK Technique
T1056.001Keylogging
- First Reported
- Aug 3, 2026
- Latest Reported
- Sep 28, 2026
Official Description
Adversaries may log user keystrokes to intercept credentials as the user types them. Keylogging is likely to be used to acquire credentials for new access opportunities when [OS Credential Dumping](https://attack.mitre.org/techniques/T1003) efforts are not effective, and may require an adversary to intercept keystrokes on a system for a substantial period of time before credentials can be successfully captured. In order to increase the likelihood of capturing credentials quickly, an adversary may also perform actions such as clearing browser cookies to force users to reauthenticate to systems.(Citation: Talos Kimsuky Nov 2021)
Keylogging is the most prevalent type of input capture, with many different ways of intercepting keystrokes.(Citation: Adventures of a Keystroke) Some methods include:
* Hooking API callbacks used for processing keystrokes. Unlike [Credential API Hooking](https://attack.mitre.org/techniques/T1056/004), this focuses solely on API functions intended for processing keystroke data.
* Reading raw keystroke data from the hardware buffer.
* Windows Registry modifications.
* Custom drivers.
* [Modify System Image](https://attack.mitre.org/techniques/T1601) may provide adversaries with hooks into the operating system of network devices to read raw keystrokes for login sessions.(Citation: Cisco Blog Legacy Device Attacks)
Keylogging is the most prevalent type of input capture, with many different ways of intercepting keystrokes.(Citation: Adventures of a Keystroke) Some methods include:
* Hooking API callbacks used for processing keystrokes. Unlike [Credential API Hooking](https://attack.mitre.org/techniques/T1056/004), this focuses solely on API functions intended for processing keystroke data.
* Reading raw keystroke data from the hardware buffer.
* Windows Registry modifications.
* Custom drivers.
* [Modify System Image](https://attack.mitre.org/techniques/T1601) may provide adversaries with hooks into the operating system of network devices to read raw keystrokes for login sessions.(Citation: Cisco Blog Legacy Device Attacks)
- Tactics
- Collection, Credential Access
- Platforms
- Linux, macOS, Network Devices, Windows
- Parent Technique
- T1056 · Input Capture
- MITRE Version
- 1.3
- Last Modified
- May 12, 2026
Reported Context (4)
- The article states that Remcos RAT can collect information through keylogging. Phishing Emails Use Fake Purchase Requests to Deliver Remcos RAT
- The article identifies keylogging as one of Remcos RAT's information-collection functions. Phishing Quote Requests Deliver Remcos RAT via Obfuscated PowerShell
- Keyboard-state API imports support the reported keystroke-monitoring capability, although the active polling loop was not fully traced. HVNC Backdoor Uses Fake Tax and DocuSign Lures to Target Latin American Organizations
- The stealer registered Windows keyboard hooks to log keystrokes. Fake Roblox Xeno Cheats Deliver Java Stealer Through Discord and Forums
CVE (1)
Malware (2)
Threat Actors (1)
MITRE ATT&CK (30)
Vendors (3)
Products (11)
Tools (10)
Industries (3)
Countries (3)
Note: Related entities, including threat actors, malware, CVEs, MITRE ATT&CK techniques, vendors, products, tools, countries, and industries, are shown when they appear in the same reporting. Their presence does not necessarily mean they were targeted, compromised, vulnerable, responsible for the activity, or directly involved in the incident.