Threadlinqs IntelligenceStart free

ATT&CK techniqueCredential AccessCollection

T1056 Input Capture

Credential AccessCollectionEnterprise

As of 2026-10-05, T1056 (Input Capture) appears in 285 tracked threats, first reported 2021-11-25 and most recently 2026-09-27, with linked actors including APT38, Sapphire Sleet, Andariel; it most often appears alongside T1027 (Obfuscated Files or Information).

Tracked threats
28551 critical, 202 high, 31 medium
First seen
2021-11-25
Last seen
2026-09-27
Threat actors
99In the threats using it
Detection rules
55Blue tier and above

Data as of:

Activity timeline

T1056 first appeared in tracked threats on and was most recently reported on . The busiest month was 2026-07 with 81 reports, and 284 of the 285 threats were reported in the twelve months to 2026-09.

How adversaries use it

T1056 Input Capture is catalogued by MITRE ATT&CK under the Credential Access and Collection tactics in the Enterprise matrix. Threadlinqs maps 285 of 2623 tracked threats (10.9%) to it; by severity that is 51 critical, 202 high, 31 medium.

Threats that use T1056 most often also use T1027 Obfuscated Files or Information (217 threats), T1071 Application Layer Protocol (207 threats), T1036 Masquerading (198 threats), T1566 Phishing (195 threats), T1204 User Execution (194 threats). These are the techniques an intrusion set tends to chain with it, so they are the natural next places to look when it is observed.

99 tracked threat actors appear in the threats that use T1056; the most frequent are APT38 (8), Sapphire Sleet (7), Andariel (6), Lazarus Group (6), Stardust Chollima (6).

Data sources

Telemetry that can reveal T1056, per MITRE ATT&CK.

  • Command — Command Execution
  • Driver — Driver Load
  • File — File Creation, File Modification
  • Module — Module Load
  • Process — OS API Execution, Process Creation, Process Metadata
  • Windows Registry — Windows Registry Key Modification

Threat actors using it

Tracked threats

The 30 most recent of 285 tracked threats that use T1056.

Detection coverage

Threadlinqs maintains 55 detection rules mapped to T1056 (SPL 16, KQL 23, Sigma 16). Rule content is available to Blue tier accounts and above; this page shows counts only.

55 detection rules (SPL/KQL/Sigma) · Blue and above. Compare plans

Sub-techniques