Hide Navigation Hide TOC Potential Keylogger Activity (965e2db9-eddb-4cf6-a986-7a967df651e4) Detects PowerShell scripts that contains reference to keystroke capturing functions Cluster A Galaxy A Cluster B Galaxy B Level Potential Keylogger Activity (965e2db9-eddb-4cf6-a986-7a967df651e4) Sigma-Rules Keylogging - T1056.001 (09a60ea3-a8d1-4ae5-976e-5783248b72a4) Attack Pattern 1 Input Capture - T1056 (bb5a00de-e086-4859-a231-fa793f6797e2) Attack Pattern Keylogging - T1056.001 (09a60ea3-a8d1-4ae5-976e-5783248b72a4) Attack Pattern 2