What is a keylogger?¶
A keylogger is software or hardware that records keystrokes.
It may be part of malware, monitoring software, a browser extension, a remote-access tool or a physical device attached to the keyboard route. Finding one creates a useful time-and-output question: what input could it actually have captured while it was operating?
Put the suspected capture on a timeline¶
Imagine a keylogging component becomes active on a shared Windows computer at 18:40. A user signs in to webmail at 18:52. A recovered local log contains text consistent with the username but no password, and the component transmits data at 19:03.
That evidence can support operation during the sign-in window and collection of the recovered text. It does not justify inventing a missing password or assuming every keystroke reached a controller.
Establish the capture conditions¶
Record:
- software package, process, extension or physical device;
- installation and active period;
- monitored account, desktop or user session;
- applications and windows in focus where that is recorded;
- configuration, filters and capture triggers;
- recovered logs, buffers or screenshots;
- storage and transmission destinations; and
- controller account or retrieval route.
A keylogger installed after the relevant login cannot explain an earlier credential loss. A logger that was disabled or filtered to another session had no demonstrated opportunity to capture the claimed input.
Hardware and software leave different evidence¶
Software keyloggers may leave process, configuration, file, memory and network records. A browser extension may also leave profile, installation and account-synchronisation evidence.
A hardware device placed between a keyboard and computer may leave little or no normal operating-system trace. Photograph and preserve its physical position, ports, identifiers and relationship to the computer before removal. Specialist examination may be needed to recover stored data safely.
Authority and controller remain separate questions¶
Some monitoring tools have authorised purposes. Establish who approved the exact installation, which people and period it covered, what notice existed and whether actual use stayed within that authority.
The device owner, logged-on account, installer and person retrieving captured output may all be different. A controller portal, subscription, payment record or remote sign-in can help connect the collection to whoever could obtain the result.
Do not test suspected keylogging software by entering real credentials. Preserve the state and use an authorised specialist method.
The decisive comparison is between the keylogger's active window, the monitored session, the recovered output and any transmission. If one of those links is missing, say exactly what the evidence still establishes rather than assuming the alleged input was captured.