Files
Angerona/documentation-payload/Cazalla/commands/keylog_start.md
T
marcos.luna 2fe9fa8254 wiki created
2025-11-06 12:23:49 +01:00

1.7 KiB

keylog_start - Start Keylogger

Start a low-level keyboard logger that captures all keystrokes from the system.

Description

The keylog_start command starts a low-level keyboard logger that captures all keystrokes from the system and streams them to Mythic in real-time. Uses Windows keyboard hooking mechanisms (SetWindowsHookEx) to intercept keyboard input at a low level. CRITICAL OPSEC RISK: Keyloggers are extremely detectable by EDR/XDR solutions.

Syntax

keylog_start

Examples

keylog_start

Features

  • Captures all keystrokes from the system and streams them to Mythic in real-time
  • Uses Windows keyboard hooking mechanisms (SetWindowsHookEx) to intercept keyboard input at a low level
  • CRITICAL OPSEC RISK: Keyloggers are extremely detectable by EDR/XDR solutions, anti-malware, and behavioral analysis engines
  • Detection is likely within minutes or hours
  • Always requires approval from a lead operator
  • Consider alternatives such as credential theft, browser credential extraction, or clipboard monitoring for better OPSEC

Output

[keylog_start] Starting keylogger...
[keylog_start] Keyboard hook installed
[keylog_start] Keylogger active

OPSEC Considerations

  • CRITICAL OPSEC RISK: Extremely detectable
  • Detection is likely within minutes or hours
  • Always requires operator approval (OPSEC pre-check blocks execution)
  • Consider alternatives for better OPSEC

OPSEC Checking, Keylogging Support


Command Category: System Operations
Requires Admin: No
MITRE ATT&CK: T1056 - Input Capture