title: Audio Capture via SoundRecorder id: 83865853-59aa-449e-9600-74b9d89a6d6e description: Detect attacker collecting audio via SoundRecorder application status: experimental author: E.M. Anhaus (orignally from Atomic Blue Detections, Endgame), oscd.community date: 2019/10/24 modified: 2019/11/11 references: - https://github.com/redcanaryco/atomic-red-team/blob/master/atomics/T1123/T1123.yaml - https://eqllib.readthedocs.io/en/latest/analytics/f72a98cb-7b3d-4100-99c3-a138b6e9ff6e.html tags: - attack.collection - attack.t1123 logsource: category: process_creation product: windows detection: selection: Image|endswith: '\SoundRecorder.exe' CommandLine|contains: '/FILE' condition: selection falsepositives: - Legitimate audio capture by legitimate user level: medium