Suspicious Input Capture and Keylogging Activity

This rule detects suspicious activity related to input capturing, keylogging, or credential access, specifically looking for corresponding 'ActionType' events in Microsoft Defender for Endpoint (DeviceEvents) logs. It alerts on processes performing these actions on devices.