Analytics Alerts
Browse the Cortex analytics alert reference.
3 alerts match the current filters. tactic: TA0009 ✕ technique: T1113 ✕
Download CSV Show ATT&CK heatmapA user took numerous screenshots Informational Identity Threat Module
A user took numerous screenshots. A valuable organization's information may have been collected in this way.
- Activation:
- 14 Days
- Training:
- 30 Days
- Test:
- 1 Hour
- Deduplication:
- 1 Day
ATT&CK tactics: Collection (TA0009)ATT&CK techniques: Screen Capture (T1113) Data Staged: Local Data Staging (T1074.001)Required data: XDR Agent with eXtended Threat Hunting (XTH)Attacker's goals: Collect data and stage it on an endpoint in the organization.Investigative actions: Check whether this activity fits the user profile. Check for any other suspicious activity related to the host and the user involved in the alert. Check if there was a suspicious file upload following the massive screenshot activity. Check whether other users in the organization used the same process for file activity.Possible collection of screen captures with Windows Problem Steps Recorder Medium
Windows Problem Steps Recorder (psr.exe), can record screen and clicks. Adversaries may abuse psr.exe to create screen captures and collect them afterward.
- Activation:
- 14 Days
- Training:
- 30 Days
- Test:
- N/A (single event)
- Deduplication:
- 1 Day
ATT&CK tactics: Collection (TA0009)ATT&CK techniques: Screen Capture (T1113)Required data: XDR AgentAttacker's goals: Evading security controls and collecting screen captures of the desktop.Investigative actions: Monitor the command-line arguments of psr.exe and the process causality. Validate the following criteria, if none of them are correct, follow incident response procedures: Check the causality of execution and if the TSS script was executed (Microsoft Troubleshooting Script). If output parameters in the command line are executed by the user. If the parent process is known in the organization as a support tool.Uncommon AppleScript designed to capture screen or clipboard data was executed via the command line Low
The AppleScript interpreter was executed with a script designed to capture screen content or clipboard data.
- Activation:
- 14 Days
- Training:
- 30 Days
- Test:
- N/A (single event)
- Deduplication:
- 1 Day
ATT&CK tactics: Execution (TA0002) Collection (TA0009)ATT&CK techniques: Command and Scripting Interpreter: AppleScript (T1059.002) Screen Capture (T1113) Clipboard Data (T1115)Required data: XDR AgentDetector tags: AppleScript Analytics, Sensitive Information Stealing AnalyticsAttacker's goals: Capture screen content or clipboard data to steal visible credentials, session tokens, or sensitive information.Investigative actions: Determine whether the screen capture or clipboard access was initiated by a legitimate application. Check if the captured data was written to a suspicious location or exfiltrated. Verify whether the user was aware of the screen capture activity.