NPPSPY records data entered from the local system logon at Winlogon to capture credentials in cleartext.3
tool
NPPSPY S1131
- Type
- tool
- Platform
- Windows
- Created
- 17 May 2024
- Last modified
- 28 October 2024
NPPSPY is an implementation of a theoretical mechanism first presented in 2004 for capturing credentials submitted to a Windows system via a rogue Network Provider API item. NPPSPY captures credentials following submission and writes them to a file on the victim system for follow-on exfiltration.[1][2]
Enterprise ATT&CK only. Any Mobile or ICS rows on the same ATT&CK page are not carried.
MITRE reference S1131
NPPSPY captures user input into the Winlogon process by redirecting RPC traffic from legitimate listening DLLs within the operating system to a newly registered malicious item that allows for recording logon information in cleartext.4
NPPSPY modifies the Registry to record the malicious listener for output from the Winlogon process.5
NPPSPY collection is automatically recorded to a specified file on the victim machine.6
NPPSPY captures credentials by recording them through an alternative network listener registered to the mpnotify.exe process, allowing for cleartext recording of logon information.7
NPPSPY opens a new network listener for the mpnotify.exe process that is typically contacted by the Winlogon process in Windows. A new, alternative RPC channel is set up with a malicious DLL recording plaintext credentials entered into Winlogon, effectively intercepting and redirecting the logon information.8
Standing S1131
Reach is how much of ATT&CK this tool touches. Coverage is how well defended each thing it does is, as a median per technique rather than a total — a total would just restate the reach. Each figure is ranked against all 825 ATT&CK software entries only where that population actually spreads. Where most of the population shares one value, a percentile would rank the tie instead of the entity, so the raw value is shown and no rank is claimed.
Reach
33rd percentile · 67% of 825 ATT&CK software entries have more Enterprise techniques.
41st percentile · 59% of 825 ATT&CK software entries have more tactics spanned.
61% of the population shares a single value across only 22 distinct values, so a percentile here would rank the tie, not the entity.
85% of the population shares a single value across only 8 distinct values, so a percentile here would rank the tie, not the entity.
Coverage
21st percentile · 79% of 825 ATT&CK software entries have more detection rules per technique.
Detection coverage S1131
242 distinct rules cover the 7 techniques recorded for this tool. The 244 technique-to-rule mappings resolve to 242 distinct rules, because one rule can cover several techniques. 139 Sigma · 103 Splunk.
Loading detections...
| Select | Title | Description | Category | Status | Event | Product | MITRE ATT&CK | CVEs | Severity | Author | Created | Updated | ID | Refs |
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
© 2026 The MITRE Corporation. ATT&CK® and D3FEND™ data reproduced with permission. SigmaHQ detection rules licensed under DRL 1.1. attack.mitre.org · d3fend.mitre.org · CAR analytics licensed under Apache 2.0 · car.mitre.org