Malicious LSA Password Filter Registration via Notification Packages

PremiumReviewedSigma · High · v1
Product
windows
Category
registry_set
Author
HuntRule
Published
2026-09-24
Updated
2026-09-24

ATT&CK techniques

Persistence → Cred Access
  1. Recon

  2. Resource Dev

  3. Initial Access

  4. Execution

  5. Priv Esc

  6. Discovery

  7. Lateral Movement

  8. Collection

  9. C2

  10. Exfiltration

  11. Impact

What it detects

This rule detects modification of the LSA Notification Packages registry value to register a rogue password filter DLL such as sasetup.dll. Operation FishMedley abused this mechanism to capture plaintext passwords during password change events via the PasswordChangeNotify export. Password filters run inside LSASS and let attackers persistently intercept credentials as users change them.

Related detections4 linkedT1556.002 — drag to rearrange
Malicious Ntospy Network Provider DLL Registration for Credential Capture
Windows Process Creation: Suspicious secedit.exe Security Policy Export or Configuration
Windows PowerShell Copies a DLL into System32 or SysWOW64
Windows Credential Access via Reg Add in LSA Registry Paths
Malicious LSA Password Filter Registration via Notification Packages
Pivot detection · T1556.002 · 4 related

Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.