Suspicious security package DLL loaded
Attackers can abuse Windows Security Support Provider and Authentication Packages to dynamically inject a Security Package into the Local Security Authority Subsystem Service process to intercept all logon passwords.
- Plataforma: Windows
- Severidad: High
- Táctica MITRE: Acceso a credenciales
- Técnicas MITRE: T1003, T1003.001