Elastic added behavioral Windows keylogger detection to Elastic Defend 8.12, using Event Tracing for Windows (ETW) to observe API activity associated with keystroke collection through polling, keyboard hooks, Raw Input, and DirectInput. Prebuilt endpoint rules identify suspicious use of APIs including GetAsyncKeyState, SetWindowsHookEx, and RegisterRawInputDevices.
In testing on Windows 10, Elastic Defend detected a proof-of-concept Raw Input keylogger soon after it executed, flagging an untrusted process that registered for keyboard input. The telemetry captures API arguments, call-stack context, process-signature status, and related process metadata, enabling defenders to investigate credential- and information-theft activity while reducing false positives from legitimate accessibility and input software.

See real exploitation activity before you spend the cycle.
2 events from the most recent confirmed update back to the earliest known activity.
In a Windows 10 22H2 test, Elastic Defend detected a proof-of-concept program named Keylogger.exe shortly after it registered for keyboard input through RegisterRawInputDevices. The "Keystroke Input Capture via RegisterRawInputDevices" rule identified the untrusted process's keyboard-capture registration.
Elastic Defend version 8.12 introduced ETW-based behavioral detections for user-space Windows keylogging activity, including suspicious use of GetAsyncKeyState, SetWindowsHookEx, and RegisterRawInputDevices. Elastic also added prebuilt endpoint rules intended to detect polling, keyboard-hook, Raw Input, and DirectInput capture methods without relying on malware signatures.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See real exploitation activity behind this advisory so you can triage it against everything else in the queue.
4 references tracked. Mallory keeps watching after this page renders.
malpedia.caad.fkie.fraunhofer.de
Open sourceelastic.co
Open sourceelastic.co
Open sourcelearn.microsoft.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.