Windows PowerShell Keylogger Function Reference in Script Block Logging
Alerts on PowerShell script blocks containing keyboard IsKeyDown references associated with potential keystroke capture.
- Product
- windows
- Category
- ps_script
- Author
- Nasreddine Bencherchali (Nextron Systems) (SigmaHQ), DRL 1.1
- Published
- 2023-01-04
- Updated
- 2026-07-31
ATT&CK techniques
Cred Access → CollectionRecon
Resource Dev
Initial Access
Execution
Persistence
Priv Esc
Defense Evasion
Cred Access
Discovery
Lateral Movement
Collection
C2
Exfiltration
Impact
What it detects
This rule flags PowerShell script text that includes a specific reference to keyboard state checks using [Windows.Input.Keyboard]::IsKeyDown with [System.Windows.Input.Key]. Such code can be used by keyloggers to capture or infer user keystrokes. It relies on Script Block Logging telemetry capturing the script content processed by PowerShell.
Reporting behind it
- twitter.comhttps://twitter.com/ScumBots/status/1610626724257046529
- virustotal.comhttps://www.virustotal.com/gui/file/d4486b63512755316625230e0c9c81655093be93876e0d80732e7eeaf7d83476/content
- virustotal.comhttps://www.virustotal.com/gui/file/720a7ee9f2178c70501d7e3f4bcc28a4f456e200486dbd401b25af6da3b4da62/content
- learn.microsoft.comhttps://learn.microsoft.com/en-us/dotnet/api/system.windows.input.keyboard.iskeydown?view=windowsdesktop-7.0
- github.comhttps://github.com/SigmaHQ/sigma/blob/master/rules/windows/powershell/powershell_script/posh_ps_susp_keylogger_activity.yml
Changelog
v2- v2Candidate ingested via manual entry.2026-07-31
- v1No changelog recorded for this version.2026-07-30
Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.
title: Windows PowerShell Keylogger Function Reference in Script Block Logging
id: 0b5d2ccc-0d6f-455d-a7cf-b6b11f175977
status: test
description: This rule flags PowerShell script text that includes a specific reference to keyboard state checks using [Windows.Input.Keyboard]::IsKeyDown with [System.Windows.Input.Key]. Such code can be used by keyloggers to capture or infer user keystrokes. It relies on Script Block Logging telemetry capturing the script content processed by PowerShell.
references:
- https://twitter.com/ScumBots/status/1610626724257046529
- https://www.virustotal.com/gui/file/d4486b63512755316625230e0c9c81655093be93876e0d80732e7eeaf7d83476/content
- https://www.virustotal.com/gui/file/720a7ee9f2178c70501d7e3f4bcc28a4f456e200486dbd401b25af6da3b4da62/content
- https://learn.microsoft.com/en-us/dotnet/api/system.windows.input.keyboard.iskeydown?view=windowsdesktop-7.0
- https://github.com/SigmaHQ/sigma/blob/master/rules/windows/powershell/powershell_script/posh_ps_susp_keylogger_activity.yml
author: Nasreddine Bencherchali (Nextron Systems), Huntrule Team
date: 2023-01-04
tags:
- attack.collection
- attack.credential-access
- attack.t1056.001
logsource:
product: windows
category: ps_script
definition: "Requirements: Script Block Logging must be enabled"
detection:
selection:
ScriptBlockText|contains: "[Windows.Input.Keyboard]::IsKeyDown([System.Windows.Input.Key]::"
condition: selection
falsepositives:
- Unknown
level: medium
license: DRL-1.1
related:
- id: 965e2db9-eddb-4cf6-a986-7a967df651e4
type: derived