CAPEC Definitions

    CAPEC Definitions / CAPEC-568

    CAPEC-568: Capture Credentials via Keylogger

    An adversary deploys a keylogger in an effort to obtain credentials directly from a system's user. After capturing all the keystrokes made by a user, the adversary can analyze the data and determine which string are likely to be passwords or other credential related information.

    Severity:High
    Possibility:

    Extended Description

    No Extended Description.

    Mitigations

    Strong physical security can help reduce the ability of an adversary to install a keylogger.

    Relationships with other CAPECs

    CAPEC-569: Collect Data as Provided by Users

    CAPEC-600: Credential Stuffing

    CAPEC-151: Identity Spoofing

    CAPEC-560: Use of Known Domain Credentials

    CAPEC-561: Windows Admin Shares with Stolen Credentials

    CAPEC-653: Use of Known Operating System Credentials

    Prerequisites

    The ability to install the keylogger, either in person or remote.

    Related Weaknesses

    No related Weaknesses found.