情報窃取から端末を守る
ID: b0f7d0d9-8bd7-586c-bfe4-df7d966d31a4
STIX ID: report--b0f7d0d9-8bd7-586c-bfe4-df7d966d31a4
Feed Name: Elastic Security Labs
This report describes Elastic Defend 8.12's new behavior-based detection capabilities for Windows keyloggers: it explains four common keylogging techniques (polling via GetAsyncKeyState, hooks via SetWindowsHookEx, Raw Input via RegisterRawInputDevices, and DirectInput), how ETW is used to monitor relevant API calls and parameters, example detection rules/queries (including a RegisterRawInputDevices detection query), and the API metadata fields Elastic collects to reduce false positives and improve keystroke-capture detection.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
