Rule Info
Name
Potential PowerShell Screen Capture via Win32 GDI BitBlt
Author
Swachchhanda Shrawan Poudel (Nextron Systems)
Description
Detects PowerShell ScriptBlock using the Win32 GDI BitBlt API to capture screen content.
Attackers use this native approach to silently copy display pixel data without dropping a
standalone capture binary, a technique commonly observed in keyloggers, RATs and spyware.
Date
2026-09-16 00:00:00
Modified
None
Id
899ad581-8fb0-4c86-9194-fcff4fa2c332
Tags
attack.collection attack.t1113
Type
Nextron Sigma feed only (private)
