{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/tags/endpoint-monitoring/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":[],"_cs_cves":[],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":[],"_cs_severities":["medium"],"_cs_tags":["collection","reconnaissance","powershell","endpoint-monitoring"],"_cs_type":"advisory","_cs_vendors":[],"content_html":"\u003cp\u003eAdversaries frequently employ screen capture techniques to exfiltrate sensitive data or monitor user activity following an initial compromise. A common, lightweight method observed in post-compromise operations involves the abuse of .NET classes available within the PowerShell environment. Specifically, attackers utilize the 'CopyFromScreen' method of the 'System.Drawing.Graphics' class to programmatically capture the desktop and save it as an image file. This technique is often integrated into custom remote access tools or lightweight reconnaissance scripts to avoid the overhead of deploying full-featured malware. Because it leverages built-in Windows APIs via PowerShell, defenders can detect this activity by monitoring PowerShell Script Block Logging for the instantiation of these specific graphics classes.\u003c/p\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful execution allows attackers to exfiltrate sensitive information visible on the victim's screen, such as credentials, internal documentation, or ongoing communications. This collection phase is a critical step in reconnaissance and exfiltration workflows, increasing the risk of data exposure for the compromised host.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eEnable PowerShell Script Block Logging (Event ID 4104) across all Windows endpoints to ensure the visibility of script content.\u003c/li\u003e\n\u003cli\u003eDeploy the provided Sigma rule to detect the use of the .CopyFromScreen method in PowerShell scripts.\u003c/li\u003e\n\u003cli\u003eEstablish an alert for PowerShell execution where the script content references 'System.Drawing.Graphics'.\u003c/li\u003e\n\u003cli\u003eAudit environments for administrative or non-standard tools that may legitimately perform screen captures.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-09-03T13:37:37Z","date_published":"2026-09-03T13:37:37Z","id":"https://feed.craftedsignal.io/briefs/2026-09-windows-screen-capture/","summary":"Adversaries use the .NET CopyFromScreen method within PowerShell scripts to capture desktop screenshots for information gathering during post-compromise operations.","title":"Windows Screen Capture via PowerShell CopyFromScreen","url":"https://feed.craftedsignal.io/briefs/2026-09-windows-screen-capture/"}],"language":"en","title":"CraftedSignal Threat Feed - Endpoint-Monitoring","version":"https://jsonfeed.org/version/1.1"}