Windows Credential Access via Reg Add in LSA Registry Paths

Alerts when reg add commands target LSA registry settings and scecli entries commonly abused for credential access.

FreeReviewedSigma · Medium · v1
Product
windows
Category
process_creation
Author
Sreeman (SigmaHQ), DRL 1.1
Published
2020-10-29
Updated
2026-07-30

ATT&CK techniques

Persistence → Cred Access
  1. Recon

  2. Resource Dev

  3. Initial Access

  4. Execution

  5. Priv Esc

  6. Discovery

  7. Lateral Movement

  8. Collection

  9. C2

  10. Exfiltration

  11. Impact

What it detects

This rule flags process creation events where the command line includes registry modification targeting the LSA configuration path and references "scecli\0*", along with the "reg add" action. Attackers may use this behavior to set up components that can impact credential handling and enable credential access. The detection relies on Windows process creation telemetry with command-line content matching the specified registry path elements.

Related detections3 linkedT1556.002 — drag to rearrange
Malicious Ntospy Network Provider DLL Registration for Credential Capture
Windows Process Creation: Suspicious secedit.exe Security Policy Export or Configuration
Windows PowerShell Copies a DLL into System32 or SysWOW64
Windows Credential Access via Reg Add in LSA Registry Paths
Pivot detection · T1556.002 · 3 related

Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.