Protect processes with high privileges that can be used to interact with critical system components through use of protected process light, anti-process injection defenses, or other process integrity enforcement measures.
| Domain | ID | Name | Use | |
|---|---|---|---|---|
| Enterprise | T1547 | .002 | Boot or Logon Autostart Execution: Authentication Package |
Windows 8.1, Windows Server 2012 R2, and later versions, may make LSA run as a Protected Process Light (PPL) by setting the Registry key |
| .005 | Boot or Logon Autostart Execution: Security Support Provider |
Windows 8.1, Windows Server 2012 R2, and later versions may make LSA run as a Protected Process Light (PPL) by setting the Registry key |
||
| .008 | Boot or Logon Autostart Execution: LSASS Driver |
On Windows 8.1 and Server 2012 R2, enable LSA Protection by setting the Registry key |
||
| Enterprise | T1556 | Modify Authentication Process |
Enabled features, such as Protected Process Light (PPL), for LSA.[4] |
|
| .001 | Domain Controller Authentication |
Enabled features, such as Protected Process Light (PPL), for LSA.[4] |
||
| Enterprise | T1003 | OS Credential Dumping |
On Windows 8.1 and Windows Server 2012 R2, enable Protected Process Light for LSA.[4] |
|
| .001 | LSASS Memory |
On Windows 8.1 and Windows Server 2012 R2, enable Protected Process Light for LSA.[4] |
||