AN0629
Analytic 0629
Windows
Unauthorized creation or modification of DLLs loaded by LSASS, abnormal registry values under LSA extensions, and anomalous DLL load activity into the lsass.exe process context—correlated during boot or logon events.
WinEventLog:Security
EventCode=3033
WinEventLog:Sysmon
EventCode=6
WinEventLog:Sysmon
EventCode=11
WinEventLog:Sysmon
EventCode=2
WinEventLog:Sysmon
EventCode=12
WinEventLog:Sysmon
EventCode=13, 14
[TimeWindow]
Correlate DLL file creation/modification with LSASS execution within a configurable timeframe (e.g., 5 min)
[ImagePathPattern]
Tune based on known legitimate LSASS plugin DLL paths
[SignatureValidation]
Flag unsigned DLLs loaded into lsass.exe or those signed by unexpected publishers
[RegistryKeyScope]
Scope to specific registry keys: HKLM\SYSTEM\CurrentControlSet\Control\Lsa\Authentication Packages
[FileHashAllowList]
Exclude known-good LSASS plugin DLLs based on cryptographic hash