Suspicious security package DLL loaded

Attackers can abuse Windows Security Support Provider and Authentication Packages to dynamically inject a Security Package into the Local Security Authority Subsystem Service process to intercept all logon passwords.

Back to all rules