What MITRE ATT&CK T1056: Input Capture (Enterprise Tactic TA0009 - Collection / TA0006 - Credential Access) requires
MITRE ATT&CK T1056 (Input Capture) is an Enterprise Collection and Credential Access technique. Adversaries may use methods of capturing user input to obtain credentials or collect information. During normal system usage, users often provide credentials to various different locations, such as login pages/portals or system dialog boxes. Input capture mechanisms may be transparent to the user (e.g. Credential API Hooking) or rely on deceiving the user into providing input into what they believe to be a genuine service (e.g. Web Portal Capture). ATT&CK documents 4 sub-techniques: T1056.001 Keylogging; T1056.002 GUI Input Capture; T1056.003 Web Portal Capture; T1056.004 Credential API Hooking. Affected platforms: Linux, macOS, Windows, Network.
Pillar: Cybersecurity · Authority: MITRE Corporation · Version: 1.0.0 · Last updated:
Primary source: https://attack.mitre.org/techniques/T1056/
SHA-256 integrity: f932225bd0a7b3b970c4db6341b2dca0bb4b56fbb4a2e3bd6dad9371bcfe21de
Primary Citations — 5 traced to source
- MITRE ATT&CK Technique T1056: Input Capture (https://attack.mitre.org/techniques/T1056/) with 4 sub-techniques
- MITRE ATT&CK Tactic TA0009: Collection (https://attack.mitre.org/tactics/TA0009/)
+ 3 more citations (full bibliography, deterministic workflow, actionable schema and crosswalks) included in the vault unlock — $0.01 via Skyfire / L402 / Direct Base USDC.
Access
⚠ Important: Human Verification Required
Bidda compliance nodes are reference intelligence, not legal advice. Every node must be reviewed by a qualified compliance professional or legal counsel before implementation in any enterprise workflow, regulated system, or compliance programme. See bidda.com/disclaimer for full terms.