{"id":"T1547.008","name":"LSASS Driver","url":"https://attack.mitre.org/techniques/T1547/008","tactics":["persistence","privilege-escalation"],"platforms":["Windows"],"live":true,"revoked":false,"deprecated":false,"revoked_by":null,"detection_strategies":[{"id":"DET0225","stix_id":"x-mitre-detection-strategy--fbac07bf-65d5-4222-88bb-0ef798417ebb","name":"Detect unauthorized LSASS driver persistence via LSA plugin abuse (Windows)","url":"https://attack.mitre.org/detectionstrategies/DET0225","analytics":[{"id":"AN0629","stix_id":"x-mitre-analytic--5028303d-22d6-490c-b053-015e877d5829","name":"Analytic 0629","description":"Unauthorized creation or modification of DLLs loaded by LSASS, abnormal registry values under LSA extensions, and anomalous DLL load activity into the lsass.exe process context—correlated during boot or logon events.","url":"https://attack.mitre.org/detectionstrategies/DET0225#AN0629","platforms":["Windows"],"log_source_references":[{"name":"WinEventLog:Security","channel":"EventCode=3033","data_component":"DC0016","data_component_name":"Module Load","log_source_slug":"wineventlog-security"},{"name":"WinEventLog:Sysmon","channel":"EventCode=6","data_component":"DC0079","data_component_name":"Driver Load","log_source_slug":"wineventlog-sysmon"},{"name":"WinEventLog:Sysmon","channel":"EventCode=11","data_component":"DC0039","data_component_name":"File Creation","log_source_slug":"wineventlog-sysmon"},{"name":"WinEventLog:Sysmon","channel":"EventCode=2","data_component":"DC0061","data_component_name":"File Modification","log_source_slug":"wineventlog-sysmon"},{"name":"WinEventLog:Sysmon","channel":"EventCode=12","data_component":"DC0056","data_component_name":"Windows Registry Key Creation","log_source_slug":"wineventlog-sysmon"},{"name":"WinEventLog:Sysmon","channel":"EventCode=13, 14","data_component":"DC0063","data_component_name":"Windows Registry Key Modification","log_source_slug":"wineventlog-sysmon"}],"mutable_elements":[{"field":"TimeWindow","description":"Correlate DLL file creation/modification with LSASS execution within a configurable timeframe (e.g., 5 min)"},{"field":"ImagePathPattern","description":"Tune based on known legitimate LSASS plugin DLL paths"},{"field":"SignatureValidation","description":"Flag unsigned DLLs loaded into lsass.exe or those signed by unexpected publishers"},{"field":"RegistryKeyScope","description":"Scope to specific registry keys: HKLM\\SYSTEM\\CurrentControlSet\\Control\\Lsa\\Authentication Packages"},{"field":"FileHashAllowList","description":"Exclude known-good LSASS plugin DLLs based on cryptographic hash"}],"live":true,"detection_strategies":["DET0225"],"techniques":["T1547.008"]}],"live":true,"version":"1.0","techniques":["T1547.008"]}],"sigma_rules":[{"id":"b3503044-60ce-4bf4-bbcb-e3db98788823","title":"DLL Load via LSASS","author":"Florian Roth (Nextron Systems)","status":"test","level":"high","date":"2019-10-16","modified":"2022-04-21","description":"Detects a method to load DLL via LSASS process using an undocumented Registry key","references":["https://blog.xpnsec.com/exploring-mimikatz-part-1/","https://twitter.com/SBousseaden/status/1183745981189427200"],"logsource":{"product":"windows","category":"registry_event"},"tags":["attack.privilege-escalation","attack.execution","attack.persistence","attack.t1547.008"],"path":"rules/windows/registry/registry_event/registry_event_susp_lsass_dll_load.yml","techniques":["T1547.008"],"cves":[]}],"kev_cves":[],"_built":"2026-08-24 19:45 UTC","_attack_version":"19.2","_sigma_commit":"da9bb07d642a2826e89702445d32c795209ec108"}