Threaticon
Toggle sidebar

You're viewing a limited, public preview. Log in for full access.

Log in User Guide
Log in Get started
Detection Strategies DET0472 — Detect Malicious Password Filter DLL Registration
DET0472

Detect Malicious Password Filter DLL Registration

1 analytic(s) · 1 technique(s) detected

Analytics

1
AN1303 Analytic 1303
Windows

Detects suspicious registration of new password filter DLLs into the authentication process. Correlates registry modifications to LSASS Notification Packages with subsequent DLL creation and loading events. Observes anomalous file placement of DLLs in system directories followed by LSASS loading the new filter during logon/password change activity.

WinEventLog:Security EventCode=4657 WinEventLog:Sysmon EventCode=11 WinEventLog:Sysmon EventCode=7
[RegistryPath] Specific registry path monitored for modification (e.g., HKLM\SYSTEM\CurrentControlSet\Control\Lsa\Notification Packages).
[AllowedDLLs] Known and approved password filter DLLs; deviations from baseline may indicate malicious injection.
[TimeWindow] Time window for correlating registry modification, file creation, and module load events.
[FilePathPatterns] Expected directories for legitimate password filter DLLs; anomalous paths may signal compromise.

Detected Techniques

1

Defense Impairment (1)

Details

MITRE ID
DET0472
STIX ID
x-mitre-detection-strategy--f722c058-8449-49ee-8e18-c3e76ec60a51
Analytics
1
Techniques Detected
1
By Tactic
Defense Impairment
1
Leaving Threaticon

This link opens an external site that isn't part of the platform.