LoFP LoFP / legitimate user activity taking screenshots

Techniques

Sample rules

Screen Capture - macOS

Description

Detects attempts to use screencapture to collect macOS screenshots

Detection logic

condition: selection
selection:
  Image: /usr/sbin/screencapture