{"id":"T1547.005","name":"Security Support Provider","url":"https://attack.mitre.org/techniques/T1547/005","tactics":["persistence","privilege-escalation"],"platforms":["Windows"],"live":true,"revoked":false,"deprecated":false,"revoked_by":null,"detection_strategies":[{"id":"DET0542","stix_id":"x-mitre-detection-strategy--6b47bf45-a3f2-4d4b-884a-3cec3ef3f994","name":"Registry and LSASS Monitoring for Security Support Provider Abuse","url":"https://attack.mitre.org/detectionstrategies/DET0542","analytics":[{"id":"AN1495","stix_id":"x-mitre-analytic--b4a380ed-cc16-47cd-8fe1-44ccf4cad097","name":"Analytic 1495","description":"Monitor registry modifications to `HKLM\\SYSTEM\\CurrentControlSet\\Control\\Lsa\\Security Packages` or `...\\OSConfig\\Security Packages`, especially insertions of new DLL entries. Correlate this with subsequent DLL module loads into `lsass.exe`. Track unsigned or anomalous DLLs loading into LSASS using image load auditing. LSASS loads unsigned DLL due to AuditLevel=8 registry configuration or System reboot followed by DLL load into lsass.exe","url":"https://attack.mitre.org/detectionstrategies/DET0542#AN1495","platforms":["Windows"],"log_source_references":[{"name":"WinEventLog:Security","channel":"EventCode=4657","data_component":"DC0063","data_component_name":"Windows Registry Key Modification","log_source_slug":"wineventlog-security"},{"name":"WinEventLog:Sysmon","channel":"EventCode=7","data_component":"DC0016","data_component_name":"Module Load","log_source_slug":"wineventlog-sysmon"},{"name":"WinEventLog:Sysmon","channel":"EventCode=1","data_component":"DC0032","data_component_name":"Process Creation","log_source_slug":"wineventlog-sysmon"}],"mutable_elements":[{"field":"TimeWindow","description":"Controls how long after registry modification to expect a DLL load into LSASS (e.g., after reboot)"},{"field":"DLLSignatureValidation","description":"Use to detect unsigned DLLs or those not matching known trusted publisher certificates"},{"field":"CustomSSPNameList","description":"Define allowed SSP values for your org to reduce false positives"},{"field":"BootContextCorrelation","description":"Whether detection should correlate boot-time registry and process events"}],"live":true,"detection_strategies":["DET0542"],"techniques":["T1547.005"]}],"live":true,"version":"1.0","techniques":["T1547.005"]}],"sigma_rules":[{"id":"eeb30123-9fbd-4ee8-aaa0-2e545bbed6dc","title":"Security Support Provider (SSP) Added to LSA Configuration","author":"iwillkeepwatch","status":"test","level":"high","date":"2019-01-18","modified":"2026-03-30","description":"Detects the addition of a SSP to the registry. Upon a reboot or API call, SSP DLLs gain access to encrypted and plaintext passwords stored in Windows.\n","references":["https://powersploit.readthedocs.io/en/latest/Persistence/Install-SSP/","https://github.com/EmpireProject/Empire/blob/08cbd274bef78243d7a8ed6443b8364acd1fc48b/data/module_source/persistence/Install-SSP.ps1#L157"],"logsource":{"product":"windows","category":"registry_event"},"tags":["attack.privilege-escalation","attack.persistence","attack.t1547.005"],"path":"rules/windows/registry/registry_event/registry_event_ssp_added_lsa_config.yml","techniques":["T1547.005"],"cves":[]}],"kev_cves":[],"_built":"2026-08-24 19:45 UTC","_attack_version":"19.2","_sigma_commit":"da9bb07d642a2826e89702445d32c795209ec108"}