Authentication Package

T1547.002

Sub-technique of T1547 Boot or Logon Autostart Execution.View on attack.mitre.org

About this technique

Adversaries may abuse authentication packages to execute DLLs when the system boots. Windows authentication package DLLs are loaded by the Local Security Authority (LSA) process at system start. They provide support for multiple logon processes and multiple security protocols to the operating system.

Adversaries can use the autostart mechanism provided by LSA authentication packages for persistence by placing a reference to a binary in the Windows Registry location HKLM\SYSTEM\CurrentControlSet\Control\Lsa\ with the key value of "Authentication Packages"=<target binary>. The binary will then be executed by the system when the authentication packages are loaded.

Detection rules1

Rules on DetectionCode tagged with T1547.002.

Sigma1

RuleLevelLog source
Potential Suspicious Activity Using SeCEditmediumwindows / process_creation

Splunk0

No Splunk rules are mapped to this technique yet.

Groups0

None recorded.

Software1

Campaigns0

None recorded.

Procedure examples1

Software1

Used byProcedure example
MalwareFlame

Flame can use Windows Authentication Packages for persistence.

References1

  1. MSDN Authentication Packages Open source
    Microsoft. (n.d.). Authentication Packages. Retrieved March 1, 2017.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.