Suspicious Input Capture and Keylogging Activity
This rule detects suspicious activity related to input capturing, keylogging, or credential access, specifically looking for corresponding 'ActionType' events in Microsoft Defender for Endpoint (DeviceEvents) logs. It alerts on processes performing these actions on devices.
Microsoft Sentinel (KQL)

