Threaticon
Toggle sidebar

You're viewing a limited, public preview. Log in for full access.

Log in User Guide
Log in Get started
Detection Strategies DET0225 — Detect unauthorized LSASS driver persistence via LSA plugin abuse (Windows)
DET0225

Detect unauthorized LSASS driver persistence via LSA plugin abuse (Windows)

1 analytic(s) · 1 technique(s) detected

Analytics

1
AN0629 Analytic 0629
Windows

Unauthorized creation or modification of DLLs loaded by LSASS, abnormal registry values under LSA extensions, and anomalous DLL load activity into the lsass.exe process context—correlated during boot or logon events.

WinEventLog:Security EventCode=3033 WinEventLog:Sysmon EventCode=6 WinEventLog:Sysmon EventCode=11 WinEventLog:Sysmon EventCode=2 WinEventLog:Sysmon EventCode=12 WinEventLog:Sysmon EventCode=13, 14
[TimeWindow] Correlate DLL file creation/modification with LSASS execution within a configurable timeframe (e.g., 5 min)
[ImagePathPattern] Tune based on known legitimate LSASS plugin DLL paths
[SignatureValidation] Flag unsigned DLLs loaded into lsass.exe or those signed by unexpected publishers
[RegistryKeyScope] Scope to specific registry keys: HKLM\SYSTEM\CurrentControlSet\Control\Lsa\Authentication Packages
[FileHashAllowList] Exclude known-good LSASS plugin DLLs based on cryptographic hash

Detected Techniques

1

Persistence (1)

Details

MITRE ID
DET0225
STIX ID
x-mitre-detection-strategy--fbac07bf-65d5-4222-88bb-0ef798417ebb
Analytics
1
Techniques Detected
1
By Tactic
Persistence
1
Leaving Threaticon

This link opens an external site that isn't part of the platform.