Skip to content
Skip to main content
Cyber Incidents & Offender Methods Technical Explainer

What is a keylogger?

A keylogger is software or hardware that records keystrokes.

It may be part of malware, monitoring software, a browser extension, a remote-access tool or a physical device attached to the keyboard route. Finding one creates a useful time-and-output question: what input could it actually have captured while it was operating?

Put the suspected capture on a timeline

Imagine a keylogging component becomes active on a shared Windows computer at 18:40. A user signs in to webmail at 18:52. A recovered local log contains text consistent with the username but no password, and the component transmits data at 19:03.

18:36Component installedInstallation alone does not show active capture.
18:40Capture becomes activeProcess and configuration define the opportunity window.
18:52Webmail sign-in occursApplication and session evidence fixes the relevant input.
18:58Local output recoveredCaptured text shows what the logger retained.
19:03Data transmission recordedNetwork evidence tests whether output left the device.

That evidence can support operation during the sign-in window and collection of the recovered text. It does not justify inventing a missing password or assuming every keystroke reached a controller.

Establish the capture conditions

Record:

  • software package, process, extension or physical device;
  • installation and active period;
  • monitored account, desktop or user session;
  • applications and windows in focus where that is recorded;
  • configuration, filters and capture triggers;
  • recovered logs, buffers or screenshots;
  • storage and transmission destinations; and
  • controller account or retrieval route.

A keylogger installed after the relevant login cannot explain an earlier credential loss. A logger that was disabled or filtered to another session had no demonstrated opportunity to capture the claimed input.

Hardware and software leave different evidence

Software keyloggers may leave process, configuration, file, memory and network records. A browser extension may also leave profile, installation and account-synchronisation evidence.

A hardware device placed between a keyboard and computer may leave little or no normal operating-system trace. Photograph and preserve its physical position, ports, identifiers and relationship to the computer before removal. Specialist examination may be needed to recover stored data safely.

Authority and controller remain separate questions

Some monitoring tools have authorised purposes. Establish who approved the exact installation, which people and period it covered, what notice existed and whether actual use stayed within that authority.

The device owner, logged-on account, installer and person retrieving captured output may all be different. A controller portal, subscription, payment record or remote sign-in can help connect the collection to whoever could obtain the result.

Do not test suspected keylogging software by entering real credentials. Preserve the state and use an authorised specialist method.

The decisive comparison is between the keylogger's active window, the monitored session, the recovered output and any transmission. If one of those links is missing, say exactly what the evidence still establishes rather than assuming the alleged input was captured.

Technical sources - checked 27 September 2026
Reference: CIM-069Cyber Incidents & Offender Methods