Security Support Provider

T1547.005

Sub-technique of T1547 Boot or Logon Autostart Execution.View on attack.mitre.org

About this technique

Adversaries may abuse security support providers (SSPs) to execute DLLs when the system boots. Windows SSP DLLs are loaded into the Local Security Authority (LSA) process at system start. Once loaded into the LSA, SSP DLLs have access to encrypted and plaintext passwords that are stored in Windows, such as any logged-on user's Domain password or smart card PINs.

The SSP configuration is stored in two Registry keys: HKLM\SYSTEM\CurrentControlSet\Control\Lsa\Security Packages and HKLM\SYSTEM\CurrentControlSet\Control\Lsa\OSConfig\Security Packages. An adversary may modify these Registry keys to add new SSPs, which will be loaded the next time the system boots, or when the AddSecurityPackage Windows API function is called.

Detection rules2

Rules on DetectionCode tagged with T1547.005.

Sigma1

RuleLevelLog source
Security Support Provider (SSP) Added to LSA Configurationhighwindows / registry_event

Splunk1

RuleTypeRiskData source
Windows Security Support Provider Reg QueryAnomalyNULLSysmon EventID 1, Windows Event Log Security 4688, CrowdStrike ProcessRollup2

Groups0

None recorded.

Software3

Campaigns0

None recorded.

Procedure examples3

Software3

Used byProcedure example
ToolEmpire

Empire can enumerate Security Support Providers (SSPs) as well as utilize PowerSploit's Install-SSP and Invoke-Mimikatz to install malicious SSPs and log authentication events.

ToolMimikatz

The Mimikatz credential dumper contains an implementation of an SSP.

ToolPowerSploit

PowerSploit's Install-SSP Persistence module can be used to establish by installing a SSP DLL.

References1

  1. Graeber 2014 Open source
    Graeber, M. (2014, October). Analysis of Malicious Security Support Provider DLLs. Retrieved March 1, 2017.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.