Windows LSA PPL Protection Setting Modification via reg.exe or PowerShell Command Line

Flags Windows command lines that alter LSA PPL-related Control\Lsa registry settings using reg.exe/PowerShell property changes.

FreeReviewedSigma · Medium · v1
Product
windows
Category
process_creation
Author
Florian Roth (Nextron Systems), Swachchhanda Shrawan Poudel (Nextron Systems) (SigmaHQ), DRL 1.1
Published
2022-03-22
Updated
2026-07-30

ATT&CK techniques

  1. Recon

  2. Resource Dev

  3. Initial Access

  4. Execution

  5. Persistence

  6. Priv Esc

  7. Defense Evasion

  8. Cred Access

  9. Discovery

  10. Lateral Movement

  11. Collection

  12. C2

  13. Exfiltration

  14. Impact

What it detects

This rule identifies command-line activity that modifies LSA protection-related registry values by targeting Control\Lsa settings such as IsPplAutoEnabled, RunAsPPL, and RunAsPPLBoot. Attackers may use this type of change to weaken protected-process settings to facilitate access to LSASS memory. It relies on process creation telemetry and matches process image names for reg.exe and PowerShell, along with specific command-line patterns indicating registry property updates.

Related detections2 linkedT1689 — drag to rearrange
Suspicious SMB Insecure Guest Authentication Activated - Native (via security)
Malicious NTLM Downgrade Attack - Reg via SYSMON (via registry_set)
Windows LSA PPL Protection Setting Modification via reg.exe or PowerShell Command Line
Pivot detection · T1689 · 2 related

Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.