# What is a Keylogger?

> A keylogger is software, firmware, or hardware that records a person’s keystrokes.

- Canonical URL: https://yellowcube.eu/glossary/keylogger/
- Publisher: Yellow Cube
- Language: en
- Contact: hello@yellowcube.eu

## Content

Keylogging can be authorized for diagnostics, testing, or disclosed monitoring, but malicious use captures credentials, messages, financial details, or other typed information without informed permission. The term describes the collection method, not the operator’s intent or every capability of the surrounding tool.

Software can intercept keyboard events, read input interfaces, or use privileged components, while hardware can sit between a keyboard and device or be concealed inside equipment. Captured data may remain local or be transmitted, sometimes as one function within spyware or a remote access trojan.

### Key points

- **Scope:** Determine whether collection covers all input, selected applications, particular fields, remote console sessions, virtual keyboards, clipboard content, or additional screen and form data.
- **Evidence:** Look for unexpected input hooks, drivers, processes, startup changes, access to device interfaces, unusual local logs, outbound transfers, and physical components attached to or hidden within equipment.
- **Risk reduction:** Control physical access, restrict software and driver installation, protect privileged accounts, monitor high-risk endpoints, and use phishing-resistant authentication that does not require a reusable secret to be typed.
- **Important limitation:** A keylogger does not capture secrets that are never entered through an observed input path, but it may still record typed one-time codes, recovery information, and sensitive text. Normal accessibility, testing, or monitoring software can produce similar evidence.

### Related terms

[Spyware](<https://yellowcube.eu/glossary/spyware/>) · [Malware](<https://yellowcube.eu/glossary/malware/>) · [Login credentials](<https://yellowcube.eu/glossary/login-credentials/>) · [Account takeover (ATO)](<https://yellowcube.eu/glossary/account-takeover/>) · [Endpoint detection and response (EDR)](<https://yellowcube.eu/glossary/endpoint-detection-and-response/>)

### Sources

[Canadian Centre for Cyber Security: Protect Your Organization from Malware](https://www.cyber.gc.ca/en/guidance/protect-your-organization-malware-itsap00057) · [MITRE ATT&CK T1056.001: Input Capture—Keylogging](https://attack.mitre.org/techniques/T1056/001/) · [NIST Glossary: Key Logger](https://csrc.nist.gov/glossary/term/key_logger)

## Attribution and scope

This Markdown representation is generated from the same approved content records as the canonical HTML page. Cite the canonical URL above when referencing this material. Product and service descriptions are informational; confirm project-specific requirements with Yellow Cube.

