Windows Registry: New Security Support Provider (SSP) added to LSA configuration

Alerts when a new SSP is added to LSA Security Packages in the Windows registry, excluding msiexec-driven changes.

FreeReviewedSigma · High · v1
Product
windows
Category
registry_event
Author
iwillkeepwatch (SigmaHQ), DRL 1.1
Published
2019-01-18
Updated
2026-07-30

ATT&CK techniques

Persistence → Priv Esc
  1. Recon

  2. Resource Dev

  3. Initial Access

  4. Execution

  5. Defense Evasion

  6. Cred Access

  7. Discovery

  8. Lateral Movement

  9. Collection

  10. C2

  11. Exfiltration

  12. Impact

What it detects

This rule flags registry writes that add a Security Support Provider entry under the LSA Security Packages locations. Adding an SSP can enable persistence and may allow attacker-controlled code paths to access credential material stored by the operating system. The detection relies on registry event telemetry that includes the written target path and the process image performing the change, excluding modifications made by msiexec.

Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.