Windows: PUA - Mouse Lock Execution

In Kaspersky's 2020 Incident Response Analyst Report they listed legitimate tool "Mouse Lock" as being used for both credential access and collection in security incidents. This rule is adapted from







Collection consists of techniques adversaries may use to gather information and the sources information is collected from that are relevant to following through on the adversary's objectives. Frequently, the next goal after collecting data is to steal (exfiltrate) the data. Common target sources include various drive types, browsers, audio, video, and email. Common collection methods include capturing screenshots and keyboard input.

Input Capture: GUI Input Capture

Adversaries may mimic common operating system GUI components to prompt users for credentials with a seemingly legitimate prompt. When programs are executed that need additional privileges than are present in the current user context, it is common for the operating system to prompt the user for proper credentials to authorize the elevated privileges for the task. Adversaries may mimic this functionality to prompt users for credentials with a seemingly legitimate prompt for a number of reasons that mimic normal usage, such as a fake installer requiring additional access or a fake malware removal suite.



Windows Sysmon via FortiSIEM Agent



No remediation guidance specified

300 seconds

eventType="Win-Sysmon-1-Create-Process" AND (product REGEXP ".*Mouse Lock.*" OR company REGEXP ".*Misc314.*" OR command REGEXP ".*Mouse Lock_.*")

COUNT(*) >= 1

command = Filter.command,
company =,
hostName = Filter.hostName,
product = Filter.product