Security Support Provider (SSP) Added to LSA Configuration

 Original Source: [Sigma source]
Title: Security Support Provider (SSP) Added to LSA Configuration
Status: test
Description:Detects the addition of a SSP to the registry. Upon a reboot or API call, SSP DLLs gain access to encrypted and plaintext passwords stored in Windows.
References:
  -https://powersploit.readthedocs.io/en/latest/Persistence/Install-SSP/
  -https://github.com/EmpireProject/Empire/blob/08cbd274bef78243d7a8ed6443b8364acd1fc48b/data/module_source/persistence/Install-SSP.ps1#L157
Author: iwillkeepwatch
Date: 2019-01-18
modified:2026-03-30
Tags:
  • -'attack.privilege-escalation'
  • -'attack.persistence'
  • -'attack.t1547.005'
Logsource:
  • category: registry_event
  • product: windows
Detection:
  selection:
    TargetObject|endswith:
      -'\Control\Lsa\Security Packages'
      -'\Control\Lsa\OSConfig\Security Packages'

  filter_main_msiexec:
    Image:
      -'C:\Windows\system32\msiexec.exe'
      -'C:\Windows\syswow64\MsiExec.exe'

  filter_main_image_null:
    Image: 'None'
  condition:selection and not 1 of filter_main_*
Falsepositives:
  -Unknown
Level: high