logo

情報窃取から端末を守る

ID: b0f7d0d9-8bd7-586c-bfe4-df7d966d31a4

STIX ID: report--b0f7d0d9-8bd7-586c-bfe4-df7d966d31a4

Feed Name: Elastic Security Labs

Threat Score
45/100

Date Published: 2020-05-30

Date Updated: 2026-04-27

...
...

This report describes Elastic Defend 8.12's new behavior-based detection capabilities for Windows keyloggers: it explains four common keylogging techniques (polling via GetAsyncKeyState, hooks via SetWindowsHookEx, Raw Input via RegisterRawInputDevices, and DirectInput), how ETW is used to monitor relevant API calls and parameters, example detection rules/queries (including a RegisterRawInputDevices detection query), and the API metadata fields Elastic collects to reduce false positives and improve keystroke-capture detection.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.