DLL Load via LSASS

 Original Source: [Sigma source]
Title: DLL Load via LSASS
Status: test
Description:Detects a method to load DLL via LSASS process using an undocumented Registry key
References:
  -https://blog.xpnsec.com/exploring-mimikatz-part-1/
  -https://twitter.com/SBousseaden/status/1183745981189427200
Author: Florian Roth (Nextron Systems)
Date: 2019-10-16
modified:2022-04-21
Tags:
  • -'attack.privilege-escalation'
  • -'attack.execution'
  • -'attack.persistence'
  • -'attack.t1547.008'
Logsource:
  • category: registry_event
  • product: windows
Detection:
  selection:
    TargetObject|contains:
      -'\CurrentControlSet\Services\NTDS\DirectoryServiceExtPt'
      -'\CurrentControlSet\Services\NTDS\LsaDbExtPt'

  filter_domain_controller:
    Image: 'C:\Windows\system32\lsass.exe'
    Details:
      -'%%systemroot%%\system32\ntdsa.dll'
      -'%%systemroot%%\system32\lsadb.dll'

  condition:selection and not 1 of filter_*
Falsepositives:
  -Unknown
Level: high