Tag
high
advisory
Detecting Windows Screen Capture via PowerShell Script
2 rules 1 TTPThis analytic detects the execution of a PowerShell script designed to capture screen images on a host, leveraging PowerShell Script Block Logging to identify specific script block text patterns associated with screen capture activities, potentially indicating an attempt to exfiltrate sensitive information via desktop screenshots.
Windows +2
screen-capture
powershell
exfiltration
apt
2r
1t
high
threat
Braodo Stealer Screen Capture in TEMP Directory
2 rules 1 TTPThis analytic detects the creation of screen capture files in the TEMP directory, specifically targeting activity associated with the Braodo stealer malware, which captures screenshots of the victim's desktop as part of its data theft activities.
Splunk Enterprise +2
Braodo Stealer
stealc-stealer
crypto-stealer
braodo-stealer
apt37
hellcat-ransomware
vip-keylogger
screen-capture
malware
2r
1t