Sub-technique of T1547 Boot or Logon Autostart Execution.View on attack.mitre.org
Adversaries may abuse security support providers (SSPs) to execute DLLs when the system boots. Windows SSP DLLs are loaded into the Local Security Authority (LSA) process at system start. Once loaded into the LSA, SSP DLLs have access to encrypted and plaintext passwords that are stored in Windows, such as any logged-on user's Domain password or smart card PINs.
The SSP configuration is stored in two Registry keys: HKLM\SYSTEM\CurrentControlSet\Control\Lsa\Security Packages and HKLM\SYSTEM\CurrentControlSet\Control\Lsa\OSConfig\Security Packages. An adversary may modify these Registry keys to add new SSPs, which will be loaded the next time the system boots, or when the AddSecurityPackage Windows API function is called.
Rules on DetectionCode tagged with T1547.005.
| Rule | Level | Log source |
|---|---|---|
| Security Support Provider (SSP) Added to LSA Configuration | high | windows / registry_event |
| Rule | Type | Risk | Data source |
|---|---|---|---|
| Windows Security Support Provider Reg Query | Anomaly | NULL | Sysmon EventID 1, Windows Event Log Security 4688, CrowdStrike ProcessRollup2 |
None recorded.
None recorded.
| Used by | Procedure example |
|---|---|
| ToolEmpire | Empire can enumerate Security Support Providers (SSPs) as well as utilize PowerSploit's |
| ToolMimikatz | The Mimikatz credential dumper contains an implementation of an SSP. |
| ToolPowerSploit | PowerSploit's |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.