{"id":"T1556.002","name":"Password Filter DLL","url":"https://attack.mitre.org/techniques/T1556/002","tactics":["defense-impairment","persistence","credential-access"],"platforms":["Windows"],"live":true,"revoked":false,"deprecated":false,"revoked_by":null,"detection_strategies":[{"id":"DET0472","stix_id":"x-mitre-detection-strategy--f722c058-8449-49ee-8e18-c3e76ec60a51","name":"Detect Malicious Password Filter DLL Registration","url":"https://attack.mitre.org/detectionstrategies/DET0472","analytics":[{"id":"AN1303","stix_id":"x-mitre-analytic--9fb6bb78-418a-483f-ae23-518ffde414d1","name":"Analytic 1303","description":"Detects suspicious registration of new password filter DLLs into the authentication process. Correlates registry modifications to LSASS Notification Packages with subsequent DLL creation and loading events. Observes anomalous file placement of DLLs in system directories followed by LSASS loading the new filter during logon/password change activity.","url":"https://attack.mitre.org/detectionstrategies/DET0472#AN1303","platforms":["Windows"],"log_source_references":[{"name":"WinEventLog:Security","channel":"EventCode=4657","data_component":"DC0063","data_component_name":"Windows Registry Key Modification","log_source_slug":"wineventlog-security"},{"name":"WinEventLog:Sysmon","channel":"EventCode=11","data_component":"DC0039","data_component_name":"File Creation","log_source_slug":"wineventlog-sysmon"},{"name":"WinEventLog:Sysmon","channel":"EventCode=7","data_component":"DC0016","data_component_name":"Module Load","log_source_slug":"wineventlog-sysmon"}],"mutable_elements":[{"field":"RegistryPath","description":"Specific registry path monitored for modification (e.g., HKLM\\SYSTEM\\CurrentControlSet\\Control\\Lsa\\Notification Packages)."},{"field":"AllowedDLLs","description":"Known and approved password filter DLLs; deviations from baseline may indicate malicious injection."},{"field":"TimeWindow","description":"Time window for correlating registry modification, file creation, and module load events."},{"field":"FilePathPatterns","description":"Expected directories for legitimate password filter DLLs; anomalous paths may signal compromise."}],"live":true,"detection_strategies":["DET0472"],"techniques":["T1556.002"]}],"live":true,"version":"1.0","techniques":["T1556.002"]}],"sigma_rules":[{"id":"63bf8794-9917-45bc-88dd-e1b5abc0ecfd","title":"Powershell Install a DLL in System Directory","author":"frack113, Nasreddine Bencherchali (Nextron Systems)","status":"test","level":"high","date":"2021-12-27","modified":"2024-01-22","description":"Uses PowerShell to install/copy a file into a system directory such as \"System32\" or \"SysWOW64\"","references":["https://github.com/redcanaryco/atomic-red-team/blob/f339e7da7d05f6057fdfcdd3742bfcf365fee2a9/atomics/T1556.002/T1556.002.md#atomic-test-1---install-and-register-password-filter-dll"],"logsource":{"product":"windows","category":"ps_script"},"tags":["attack.persistence","attack.credential-access","attack.defense-impairment","attack.t1556.002"],"path":"rules/windows/powershell/powershell_script/posh_ps_copy_item_system_directory.yml","techniques":["T1556.002"],"cves":[]},{"id":"b7966f4a-b333-455b-8370-8ca53c229762","title":"Dropping Of Password Filter DLL","author":"Sreeman","status":"test","level":"medium","date":"2020-10-29","modified":"2022-10-09","description":"Detects dropping of dll files in system32 that may be used to retrieve user credentials from LSASS","references":["https://pentestlab.blog/2020/02/10/credential-access-password-filter-dll/","https://github.com/3gstudent/PasswordFilter/tree/master/PasswordFilter"],"logsource":{"product":"windows","category":"process_creation"},"tags":["attack.persistence","attack.credential-access","attack.defense-impairment","attack.t1556.002"],"path":"rules/windows/process_creation/proc_creation_win_reg_credential_access_via_password_filter.yml","techniques":["T1556.002"],"cves":[]},{"id":"c2c76b77-32be-4d1f-82c9-7e544bdfe0eb","title":"Potential Suspicious Activity Using SeCEdit","author":"Janantha Marasinghe","status":"test","level":"medium","date":"2022-11-18","modified":"2022-12-30","description":"Detects potential suspicious behaviour using secedit.exe. Such as exporting or modifying the security policy","references":["https://blueteamops.medium.com/secedit-and-i-know-it-595056dee53d","https://learn.microsoft.com/en-us/windows-server/administration/windows-commands/secedit"],"logsource":{"product":"windows","category":"process_creation"},"tags":["attack.collection","attack.discovery","attack.persistence","attack.credential-access","attack.privilege-escalation","attack.execution","attack.stealth","attack.defense-impairment","attack.t1685.001","attack.t1547.001","attack.t1505.005","attack.t1556.002","attack.t1685","attack.t1574.007","attack.t1564.002","attack.t1546.008","attack.t1546.007","attack.t1547.014","attack.t1547.010","attack.t1547.002","attack.t1557","attack.t1082"],"path":"rules/windows/process_creation/proc_creation_win_secedit_execution.yml","techniques":["T1685.001","T1547.001","T1505.005","T1556.002","T1685","T1574.007","T1564.002","T1546.008","T1546.007","T1547.014","T1547.010","T1547.002","T1557","T1082"],"cves":[]}],"kev_cves":[],"_built":"2026-08-23 05:47 UTC","_attack_version":"19.2","_sigma_commit":"da9bb07d642a2826e89702445d32c795209ec108"}