Keylogging (T1417.001)

View on ATT&CK

In Playbook

Technique & Subtechniques

Associated Tactics

  • Collection
  • Credential Access

Collection (TA0035)

The adversary is trying to gather data of interest to their goal. Collection consists of techniques used to identify and gather information, such as sensitive files, from a target network prior to exfiltration. This category also covers locations on a system or network where the adversary may look for information to exfiltrate.

View on ATT&CK

Procedure Examples

Description Source(s)
Lenny Zeltser. (2016, July 30). Security of Third-Party Keyboard Apps on Mobile Devices. Retrieved December 21, 2016. Zeltser-Keyboard
NIST Mobile Threat Catalogue