What is a keylogger?¶
A keylogger is software or hardware used to record keystrokes.
Avoid the dangerous assumption¶
The dangerous assumption is that finding a keylogger proves every password or message typed on the device was captured.
It does not.
A keylogger may operate:
- as malware
- as part of legitimate monitoring software
- through a malicious browser extension
- through a physical device
- within remote-access software
- as one function of a wider tool.
Investigators should identify:
- when it was installed
- when it ran
- which user sessions it monitored
- where captured data was stored
- whether data was transmitted
- who could access the output.
Relevant evidence may include installation records, process activity, configuration files, log files, captured text, network connections, account details and physical examination of the device.
The existence of a keylogger demonstrates capability. It may also support an inference about how credentials or information were obtained.
But do not assume it captured a specific entry without timing and output evidence.
A keylogger installed after the relevant login cannot explain earlier credential theft.
The device may also have been unused while the keylogger was active.
Legitimate use remains possible in some environments, but authority, notice and purpose must be examined.
Do not test suspected keylogging software by entering real credentials.
Hardware keyloggers may not create normal software artefacts. Examine connections, adapters and peripheral devices where the circumstances support it, and record who had physical access during the relevant period.
Operational takeaway¶
Establish when the keylogger operated, what input it captured and where the output went before linking it to specific stolen information.