Threaticon
Toggle sidebar

You're viewing a limited, public preview. Log in for full access.

Log in User Guide
Log in Get started
Detection Strategies DET0580 — Detect Network Provider DLL Registration and Credential Capture
DET0580

Detect Network Provider DLL Registration and Credential Capture

1 analytic(s) · 1 technique(s) detected

Analytics

1
AN1598 Analytic 1598
Windows

Detects registration of new or modified network provider DLLs via registry changes, anomalous file creation of DLLs in system directories, and suspicious process activity (mpnotify.exe interacting with non-standard DLLs). Multi-event correlation ties registry modification events to subsequent DLL loads during user logon activity.

WinEventLog:Security EventCode=4657 WinEventLog:Sysmon EventCode=11 WinEventLog:Sysmon EventCode=10 WinEventLog:Sysmon EventCode=7
[MonitoredRegistryKeys] Specific registry keys to monitor for DLL registration (e.g., NetworkProvider Order).
[SuspiciousDLLPaths] Directories or file name patterns outside of normal system DLL locations.
[TimeWindow] Window correlating registry modification, DLL creation, and subsequent logon activity.

Detected Techniques

1

Defense Impairment (1)

Details

MITRE ID
DET0580
STIX ID
x-mitre-detection-strategy--552a7d85-4ac4-48cd-9072-61a4c6b2c682
Analytics
1
Techniques Detected
1
By Tactic
Defense Impairment
1
Leaving Threaticon

This link opens an external site that isn't part of the platform.