{"id":"T1556.008","name":"Network Provider DLL","url":"https://attack.mitre.org/techniques/T1556/008","tactics":["defense-impairment","persistence","credential-access"],"platforms":["Windows"],"live":true,"revoked":false,"deprecated":false,"revoked_by":null,"detection_strategies":[{"id":"DET0580","stix_id":"x-mitre-detection-strategy--552a7d85-4ac4-48cd-9072-61a4c6b2c682","name":"Detect Network Provider DLL Registration and Credential Capture","url":"https://attack.mitre.org/detectionstrategies/DET0580","analytics":[{"id":"AN1598","stix_id":"x-mitre-analytic--c94f0795-ef0b-4e22-8395-bbba4f28346f","name":"Analytic 1598","description":"Detects registration of new or modified network provider DLLs via registry changes, anomalous file creation of DLLs in system directories, and suspicious process activity (mpnotify.exe interacting with non-standard DLLs). Multi-event correlation ties registry modification events to subsequent DLL loads during user logon activity.","url":"https://attack.mitre.org/detectionstrategies/DET0580#AN1598","platforms":["Windows"],"log_source_references":[{"name":"WinEventLog:Security","channel":"EventCode=4657","data_component":"DC0063","data_component_name":"Windows Registry Key Modification","log_source_slug":"wineventlog-security"},{"name":"WinEventLog:Sysmon","channel":"EventCode=11","data_component":"DC0039","data_component_name":"File Creation","log_source_slug":"wineventlog-sysmon"},{"name":"WinEventLog:Sysmon","channel":"EventCode=10","data_component":"DC0035","data_component_name":"Process Access","log_source_slug":"wineventlog-sysmon"},{"name":"WinEventLog:Sysmon","channel":"EventCode=7","data_component":"DC0016","data_component_name":"Module Load","log_source_slug":"wineventlog-sysmon"}],"mutable_elements":[{"field":"MonitoredRegistryKeys","description":"Specific registry keys to monitor for DLL registration (e.g., NetworkProvider Order)."},{"field":"SuspiciousDLLPaths","description":"Directories or file name patterns outside of normal system DLL locations."},{"field":"TimeWindow","description":"Window correlating registry modification, DLL creation, and subsequent logon activity."}],"live":true,"detection_strategies":["DET0580"],"techniques":["T1556.008"]}],"live":true,"version":"1.0","techniques":["T1556.008"]}],"sigma_rules":[],"kev_cves":[],"_built":"2026-08-23 05:47 UTC","_attack_version":"19.2","_sigma_commit":"da9bb07d642a2826e89702445d32c795209ec108"}