Threaticon
Toggle sidebar

You're viewing a limited, public preview. Log in for full access.

Log in User Guide
Log in Get started
Detection Strategies DET0271 — Detect Domain Controller Authentication Process Modification (Skeleton Key)
DET0271

Detect Domain Controller Authentication Process Modification (Skeleton Key)

1 analytic(s) · 1 technique(s) detected

Analytics

1
AN0757 Analytic 0757
Windows

Detects anomalous process access to LSASS on domain controllers, suspicious module loads of authentication DLLs, and registry or file modifications indicative of Skeleton Key–style patching. Correlates LSASS access attempts with subsequent abnormal logon activity patterns.

WinEventLog:Sysmon EventCode=10 WinEventLog:Sysmon EventCode=7 WinEventLog:Security EventCode=4624, 4648 WinEventLog:System Unexpected modification to lsass.exe or cryptdll.dll
[MonitoredDLLs] Specific authentication DLLs such as cryptdll.dll and samsrv.dll monitored for tampering.
[TimeWindow] Correlation window between LSASS memory access, module load, and suspicious logons.
[UserContext] Baseline expected accounts performing domain controller logon operations.

Detected Techniques

1

Details

MITRE ID
DET0271
STIX ID
x-mitre-detection-strategy--3ac249d7-5e15-47b4-a507-18d94b11de4d
Analytics
1
Techniques Detected
1
By Tactic
Defense Impairment
1
Leaving Threaticon

This link opens an external site that isn't part of the platform.