Threaticon
Toggle sidebar

You're viewing a limited, public preview. Log in for full access.

Log in User Guide
Log in Get started
Detection Strategies DET0542 — Registry and LSASS Monitoring for Security Support Provider Abuse
DET0542

Registry and LSASS Monitoring for Security Support Provider Abuse

1 analytic(s) · 1 technique(s) detected

Analytics

1
AN1495 Analytic 1495
Windows

Monitor registry modifications to `HKLM\SYSTEM\CurrentControlSet\Control\Lsa\Security Packages` or `...\OSConfig\Security Packages`, especially insertions of new DLL entries. Correlate this with subsequent DLL module loads into `lsass.exe`. Track unsigned or anomalous DLLs loading into LSASS using image load auditing. LSASS loads unsigned DLL due to AuditLevel=8 registry configuration or System reboot followed by DLL load into lsass.exe

WinEventLog:Security EventCode=4657 WinEventLog:Sysmon EventCode=7 WinEventLog:Sysmon EventCode=1
[TimeWindow] Controls how long after registry modification to expect a DLL load into LSASS (e.g., after reboot)
[DLLSignatureValidation] Use to detect unsigned DLLs or those not matching known trusted publisher certificates
[CustomSSPNameList] Define allowed SSP values for your org to reduce false positives
[BootContextCorrelation] Whether detection should correlate boot-time registry and process events

Detected Techniques

1

Details

MITRE ID
DET0542
STIX ID
x-mitre-detection-strategy--6b47bf45-a3f2-4d4b-884a-3cec3ef3f994
Analytics
1
Techniques Detected
1
By Tactic
Persistence
1
Leaving Threaticon

This link opens an external site that isn't part of the platform.