Potential PowerShell Keylogger via Low-Level Keyboard Hook

Rule Info

Name
Potential PowerShell Keylogger via Low-Level Keyboard Hook
Author
Swachchhanda Shrawan Poudel (Nextron Systems), Jonathan Peters (Nextron Systems)
Description
Detects PowerShell ScriptBlock containing inline C# that installs a low-level keyboard hook via SetWindowsHookEx with the WH_KEYBOARD_LL hook type. Attackers use Add-Type to compile and execute a keylogger entirely in memory, intercepting all keystrokes system-wide without dropping a standalone binary to disk. The presence of CallNextHookEx confirms a chained hook implementation, distinguishing it from benign API references.
Date
2026-09-16 00:00:00
Modified
None
Id
ff017594-769c-4d98-8d9e-4f3e12c744bd
Tags
attack.collection attack.credential-access attack.t1056.001
Type
Nextron Sigma feed only (private)

Rule History