Rule Info
Name
Potential PowerShell Keylogger via Low-Level Keyboard Hook
Author
Swachchhanda Shrawan Poudel (Nextron Systems), Jonathan Peters (Nextron Systems)
Description
Detects PowerShell ScriptBlock containing inline C# that installs a low-level keyboard hook
via SetWindowsHookEx with the WH_KEYBOARD_LL hook type. Attackers use Add-Type to compile
and execute a keylogger entirely in memory, intercepting all keystrokes system-wide without
dropping a standalone binary to disk. The presence of CallNextHookEx confirms a chained hook
implementation, distinguishing it from benign API references.
Date
2026-09-16 00:00:00
Modified
None
Id
ff017594-769c-4d98-8d9e-4f3e12c744bd
Tags
attack.collection attack.credential-access attack.t1056.001
Type
Nextron Sigma feed only (private)
