Ask HN: Latest best practices to detect keyloggers on Windows/Mac/Linux?
Other than your everyday well-known antivirus techniques (e.g., looking at signatures of executables and comparing to a known list of viruses), are there any super reliable ways using low-level kernel operations to see any running executable/service that is accessing keyboard events?
Even if it's a big list, if you could eliminate most of the processes because they are known applications (say, by crowdsourcing a list of known safe processes), you could come up with a subset of them and decide for yourself if any look suspicious.
The best approach should be able to detect and stop even a custom tailored attack on a high value target, where none of the code is reused from known exploits, and every trick in the book is used to obfuscate and evade automated detection. I feel like an open source package like this that had been inspected by a lot of smart people and vetted to work reliably under Windows/Mac/Linux would be a huge benefit to global security.