{"id":"T1547.002","name":"Authentication Package","url":"https://attack.mitre.org/techniques/T1547/002","tactics":["persistence","privilege-escalation"],"platforms":["Windows"],"live":true,"revoked":false,"deprecated":false,"revoked_by":null,"detection_strategies":[{"id":"DET0207","stix_id":"x-mitre-detection-strategy--1525b951-a0fb-42ac-97b7-05ac6f412020","name":"Detect LSA Authentication Package Persistence via Registry and LSASS DLL Load","url":"https://attack.mitre.org/detectionstrategies/DET0207","analytics":[{"id":"AN0583","stix_id":"x-mitre-analytic--d415367c-3624-4a68-a2b7-4734662db190","name":"Analytic 0583","description":"Registry modification of the LSA Authentication Packages key followed by LSASS loading a non-standard or unsigned DLL. This includes unusual write access to `HKLM\\SYSTEM\\CurrentControlSet\\Control\\Lsa`, especially during non-installation timeframes. Correlated with `lsass.exe` loading DLLs not present in baseline or lacking valid signatures.","url":"https://attack.mitre.org/detectionstrategies/DET0207#AN0583","platforms":["Windows"],"log_source_references":[{"name":"WinEventLog:Security","channel":"EventCode=4657","data_component":"DC0063","data_component_name":"Windows Registry Key Modification","log_source_slug":"wineventlog-security"},{"name":"WinEventLog:Sysmon","channel":"EventCode=7","data_component":"DC0016","data_component_name":"Module Load","log_source_slug":"wineventlog-sysmon"}],"mutable_elements":[{"field":"TimeWindow","description":"Time between registry write and DLL load; tune based on reboot cycles or scheduled maintenance"},{"field":"ImageSignatureStatus","description":"Allow listing of known signed LSASS-authenticated DLLs versus unknown/untrusted ones"},{"field":"RegistryPathScope","description":"Allow tuning for subkeys beyond just `Authentication Packages` (e.g., `Security Packages`, `Notification Packages`)"},{"field":"UserContext","description":"Correlate user responsible for registry edit; tune for expected administrative/service accounts"},{"field":"ParentProcess","description":"Validate process lineage for registry modification; expected tools like `reg.exe` or `powershell.exe`"}],"live":true,"detection_strategies":["DET0207"],"techniques":["T1547.002"]}],"live":true,"version":"1.0","techniques":["T1547.002"]}],"sigma_rules":[{"id":"c2c76b77-32be-4d1f-82c9-7e544bdfe0eb","title":"Potential Suspicious Activity Using SeCEdit","author":"Janantha Marasinghe","status":"test","level":"medium","date":"2022-11-18","modified":"2022-12-30","description":"Detects potential suspicious behaviour using secedit.exe. Such as exporting or modifying the security policy","references":["https://blueteamops.medium.com/secedit-and-i-know-it-595056dee53d","https://learn.microsoft.com/en-us/windows-server/administration/windows-commands/secedit"],"logsource":{"product":"windows","category":"process_creation"},"tags":["attack.collection","attack.discovery","attack.persistence","attack.credential-access","attack.privilege-escalation","attack.execution","attack.stealth","attack.defense-impairment","attack.t1685.001","attack.t1547.001","attack.t1505.005","attack.t1556.002","attack.t1685","attack.t1574.007","attack.t1564.002","attack.t1546.008","attack.t1546.007","attack.t1547.014","attack.t1547.010","attack.t1547.002","attack.t1557","attack.t1082"],"path":"rules/windows/process_creation/proc_creation_win_secedit_execution.yml","techniques":["T1685.001","T1547.001","T1505.005","T1556.002","T1685","T1574.007","T1564.002","T1546.008","T1546.007","T1547.014","T1547.010","T1547.002","T1557","T1082"],"cves":[]}],"kev_cves":[],"_built":"2026-08-24 19:45 UTC","_attack_version":"19.2","_sigma_commit":"da9bb07d642a2826e89702445d32c795209ec108"}