Threaticon
Toggle sidebar

You're viewing a limited, public preview. Log in for full access.

Log in User Guide
Log in Get started
Detection Strategies DET0207 — Detect LSA Authentication Package Persistence via Registry and LSASS DLL Load
DET0207

Detect LSA Authentication Package Persistence via Registry and LSASS DLL Load

1 analytic(s) · 1 technique(s) detected

Analytics

1
AN0583 Analytic 0583
Windows

Registry modification of the LSA Authentication Packages key followed by LSASS loading a non-standard or unsigned DLL. This includes unusual write access to `HKLM\SYSTEM\CurrentControlSet\Control\Lsa`, especially during non-installation timeframes. Correlated with `lsass.exe` loading DLLs not present in baseline or lacking valid signatures.

WinEventLog:Security EventCode=4657 WinEventLog:Sysmon EventCode=7
[TimeWindow] Time between registry write and DLL load; tune based on reboot cycles or scheduled maintenance
[ImageSignatureStatus] Allow listing of known signed LSASS-authenticated DLLs versus unknown/untrusted ones
[RegistryPathScope] Allow tuning for subkeys beyond just `Authentication Packages` (e.g., `Security Packages`, `Notification Packages`)
[UserContext] Correlate user responsible for registry edit; tune for expected administrative/service accounts
[ParentProcess] Validate process lineage for registry modification; expected tools like `reg.exe` or `powershell.exe`

Detected Techniques

1

Details

MITRE ID
DET0207
STIX ID
x-mitre-detection-strategy--1525b951-a0fb-42ac-97b7-05ac6f412020
Analytics
1
Techniques Detected
1
By Tactic
Persistence
1
Leaving Threaticon

This link opens an external site that isn't part of the platform.