[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$f2RfJrofJHTf1YOs8O7tCZm88q9wcLB6Tp8HXc78hrTg":3},{"id":4,"question":5,"answer":6,"answerHtml":7,"slug":8,"keywords":9,"article":10,"status":34,"aiModel":39,"aiConfidence":39,"updatedAt":51,"createdAt":51,"_status":50},980,"What is Additional LSA Protection and how do you configure it on Windows?","Additional LSA Protection is a security feature introduced in Windows 8.1 that prevents unsigned code from being loaded into the Local Security Authority (LSA) process. To configure it, you set the registry key `HKLM\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Image File Execution Options\\LSASS.exe` with a DWORD value `AuditLevel` set to `00000008`, then restart the system. This is detailed in the article [Configure Additional LSA Protection to monitor Password Filter DLL](\u002Fnews\u002Fconfigure-additional-lsa-protection-to-monitor-password-filter-dll).","\u003Cp>Additional LSA Protection is a security feature introduced in Windows 8.1 that prevents unsigned code from being loaded into the Local Security Authority (LSA) process. To configure it, you set the registry key `HKLM\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Image File Execution Options\\LSASS.exe` with a DWORD value `AuditLevel` set to `00000008`, then restart the system. This is detailed in the article [Configure Additional LSA Protection to monitor Password Filter DLL](\u002Fnews\u002Fconfigure-additional-lsa-protection-to-monitor-password-filter-dll).\u003C\u002Fp>\u003Cp>\u003Ca href=\"\u002Fnews\u002Fconfigure-additional-lsa-protection-to-monitor-password-filter-dll\">Read the related One Day Sec article\u003C\u002Fa>\u003C\u002Fp>","what-is-additional-lsa-protection-and-how-do-you-configure-it-on-windows-1777480989985","Additional LSA Protection, LSASS, registry, Windows security, code integrity",{"id":11,"title":12,"slug":13,"description":14,"content":15,"contentHtml":30,"cover":31,"author":32,"views":19,"readingTime":33,"status":34,"publishedAt":35,"seo":36,"tags":41,"qaPairs":42,"meta":47,"updatedAt":48,"createdAt":49,"_status":50},240,"Configure Additional LSA Protection to monitor Password Filter DLL","configure-additional-lsa-protection-to-monitor-password-filter-dll","Learn to configure additional LSA protection, monitor Password Filter DLLs, and explore exploitation techniques for enhanced Windows security and threat detection.",{"root":16},{"type":17,"format":18,"indent":19,"version":20,"children":21,"direction":29},"root","",0,1,[22],{"type":23,"format":18,"indent":19,"version":20,"children":24,"direction":29},"paragraph",[25],{"mode":26,"text":27,"type":28,"style":18,"detail":19,"format":19,"version":20},"normal","\u003Chtml>\u003Chead>\u003C\u002Fhead>\u003Cbody>\u003Ch2>0x00 Preface\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>In response to wyzzoo's comment on the article 'Application of Password Filter DLL in Penetration Testing', reminding attention to issues to consider on higher version systems, the address is as follows:\u003C\u002Fp>\u003Cp>An open-source project\u003C\u002Fp>\u003Cp>Therefore, I conducted research on this part and compiled it into an article\u003C\u002Fp>\u003Ch2>0x01 Introduction\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>This article will cover the following:\u003C\u002Fp>\u003Cul>\u003Cli>How to configure additional LSA protection\u003C\u002Fli>\u003Cli>How to obtain monitoring results\u003C\u002Fli>\u003Cli>Supplement an exploitation idea for Password Filter DLL\u003C\u002Fli>\u003Cli>Utilize the detection effectiveness of Additional LSA Protection\u003C\u002Fli>\u003C\u002Ful>\u003Ch2>0x02 Configure additional LSA protection\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>Refer to official documentation:\u003C\u002Fp>\u003Cp>https:\u002F\u002Fdocs.microsoft.com\u002Fen-us\u002Fwindows-server\u002Fsecurity\u002Fcredentials-protection-and-management\u002Fconfiguring-additional-lsa-protection\u003C\u002Fp>\u003Cp>Starting from Windows 8.1, additional protection is provided for LSA to prevent memory reading and code injection by unprotected processes\u003C\u002Fp>\u003Ch3>Protection method:\u003C\u002Fh3>\u003Cp>Requires any plugins loaded into LSA to be digitally signed with a Microsoft signature\u003C\u002Fp>\u003Cp>Specifically, digital signature refers to catalog signature, which must meet WHQL certification\u003C\u002Fp>\u003Cp>Reference materials:\u003C\u002Fp>\u003Cp>https:\u002F\u002Fdocs.microsoft.com\u002Fzh-cn\u002Fwindows-hardware\u002Fdrivers\u002Finstall\u002Fwhql-release-signature\u003C\u002Fp>\u003Cp>There is an article introducing catalog signature: 'CAT File Digital Signature Usage Tips'\u003C\u002Fp>\u003Cp>Test system: Win8.1 x64\u003C\u002Fp>\u003Ch3>Configuration method:\u003C\u002Fh3>\u003Ch4>1. The operating system must meet the conditions:\u003C\u002Fh4>\u003Cp>Windows 8.1 or newer systems\u003C\u002Fp>\u003Ch4>2. Modify the registry\u003C\u002Fh4>\u003Cp>Registry location HKLM\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Image File Execution Options\\LSASS.exe, create a new DWORD entry AuditLevel with value 00000008\u003C\u002Fp>\u003Cp>The corresponding cmd command is as follows:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>REG ADD \"HKLM\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Image File Execution Options\\LSASS.exe\" \u002Fv \"AuditLevel\" \u002Ft REG_DWORD \u002Fd \"00000008\" \u002Ff\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Ch4>3. Restart the system\u003C\u002Fh4>\u003Ch2>0x03 Obtain monitoring results\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>View logs Event 3065 and Event 3066\u003C\u002Fp>\u003Cp>Event 3065: This event records that a code integrity check determined a process (typically lsass.exe) attempted to load a specific driver that did not meet the security requirements for shared sections. However, the image was allowed to load due to configured system policies.\u003C\u002Fp>\u003Cp>Event 3066: This event records that a code integrity check determined a process (typically lsass.exe) attempted to load a specific driver that did not meet Microsoft's signature level requirements. However, the image was allowed to load due to configured system policies.\u003C\u002Fp>\u003Cp>Location: Applications and Services Logs\\Microsoft\\Windows\\CodeIntegrity\u003C\u002Fp>\u003Cp>Can log non-compliant DLLs but did not prevent the DLL from loading, as shown in the figure below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fuploads\u002Fdocx_image_1770016179279_0_c9a46349fd.jpeg\">\u003C\u002Fp>\u003Cp>Query logs Event 3065 and Event 3066 via command line:\u003C\u002Fp>\u003Cp>Get log category list:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>wevtutil el &gt;1.txt\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>Found that the corresponding entry for CodeIntegrity is Microsoft-Windows-CodeIntegrity\u002FOperational\u003C\u002Fp>\u003Cp>Search for Event 3065 and Event 3066:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>wevtutil qe Microsoft-Windows-CodeIntegrity\u002FOperational \u002Frd:true \u002Ff:text \u002Fq:\"*[system\u002Feventid=3065 and 3066]\"\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>As shown in the figure below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fuploads\u002Fdocx_image_1770016181488_1_b4a5803f1f.jpeg\">\u003C\u002Fp>\u003Cp>\u003Cstrong>Supplement:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>Delete CodeIntegrity logs:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>wevtutil cl \"Microsoft-Windows-CodeIntegrity\u002FOperational\"\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Ch2>0x04 Supplement: An exploitation approach for Password Filter DLL—achieving DLL \"hiding\" using Long UNC filename spoofing\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>For specific hiding details, refer to the article \"Catalog Signature Forgery—Long UNC Filename Spoofing\"\u003C\u002Fp>\u003Ch3>1. Name the DLL in Long UNC filename format and save it under %windir%\\system32\\\u003C\u002Fh3>\u003Cp>The lsass.exe process loads scecli.dll by default, so choose to disguise the DLL as scecli.dll\u003C\u002Fp>\u003Cp>Command line:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>type Win32Project3.dll &gt; \"\\\\?\\C:\\windows\\system32\\scecli.dll \"\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>\u003Cstrong>Note:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>There is a space after the name scecli.dll\u003C\u002Fp>\u003Ch3>2. Obtain the short file name of the dll\u003C\u002Fh3>\u003Cp>Command line:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>dir \u002Fx scecli*.dll\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>Obtain the short file name SCECLI~1.DLL, as shown in the figure below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fuploads\u002Fdocx_image_1770016182675_2_79187055a4.jpeg\">\u003C\u002Fp>\u003Ch3>3. Modify the registry key value\u003C\u002Fh3>\u003Cp>Read the key value:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>REG QUERY \"HKLM\\SYSTEM\\CurrentControlSet\\Control\\Lsa\" \u002Fv \"Notification Packages\"\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>Add dll:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>REG ADD \"HKLM\\SYSTEM\\CurrentControlSet\\Control\\Lsa\" \u002Fv \"Notification Packages\" \u002Ft REG_MULTI_SZ \u002Fd \"scecli\\0SCECLI~1.DLL\" \u002Ff\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Ch3>4. Restart\u003C\u002Fh3>\u003Cp>Use Process Explorer to view the dlls loaded by the lsass process\u003C\u002Fp>\u003Cp>Shows loading two identical scecli.dlls, with specific attribute differences, as shown in the figure below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fuploads\u002Fdocx_image_1770016183938_3_50f8963324.jpeg\">\u003C\u002Fp>\u003Ch3>5. Detection\u003C\u002Fh3>\u003Cp>Event 3066 successfully detected, as shown in the figure below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fuploads\u002Fdocx_image_1770016185457_4_c9df7281f4.jpeg\">\u003C\u002Fp>\u003Ch2>0x05 Supplement\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>1. Adding a forged Microsoft Authenticode signature to the Password Filter DLL and modifying the certificate verification mechanism to make it effective still cannot bypass Additional LSA Protection monitoring, because the Password Filter DLL requires a legitimate catalog signature, not an Authenticode signature\u003C\u002Fp>\u003Cp>2. Creating a catalog signature for the Password Filter DLL and adding it to the system's security catalog database still cannot bypass Additional LSA Protection monitoring\u003C\u002Fp>\u003Ch2>0x06 Summary\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>This article introduces the method and detection effectiveness of configuring Additional LSA Protection to monitor Password Filter DLLs. If the Password Filter DLL does not have a legitimate catalog signature, the system can successfully detect it, but by default, it will not prevent loading\u003C\u002Fp>\u003C\u002Fbody>\u003C\u002Fhtml>","text","ltr","\u003Chtml>\u003Chead>\u003C\u002Fhead>\u003Cbody>\u003Ch2>0x00 Preface\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>In response to wyzzoo's comment on the article 'Application of Password Filter DLL in Penetration Testing', reminding attention to issues to consider on higher version systems, the address is as follows:\u003C\u002Fp>\u003Cp>An open-source project\u003C\u002Fp>\u003Cp>Therefore, I conducted research on this part and compiled it into an article\u003C\u002Fp>\u003Ch2>0x01 Introduction\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>This article will cover the following:\u003C\u002Fp>\u003Cul>\u003Cli>How to configure additional LSA protection\u003C\u002Fli>\u003Cli>How to obtain monitoring results\u003C\u002Fli>\u003Cli>Supplement an exploitation idea for Password Filter DLL\u003C\u002Fli>\u003Cli>Utilize the detection effectiveness of Additional LSA Protection\u003C\u002Fli>\u003C\u002Ful>\u003Ch2>0x02 Configure additional LSA protection\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>Refer to official documentation:\u003C\u002Fp>\u003Cp>https:\u002F\u002Fdocs.microsoft.com\u002Fen-us\u002Fwindows-server\u002Fsecurity\u002Fcredentials-protection-and-management\u002Fconfiguring-additional-lsa-protection\u003C\u002Fp>\u003Cp>Starting from Windows 8.1, additional protection is provided for LSA to prevent memory reading and code injection by unprotected processes\u003C\u002Fp>\u003Ch3>Protection method:\u003C\u002Fh3>\u003Cp>Requires any plugins loaded into LSA to be digitally signed with a Microsoft signature\u003C\u002Fp>\u003Cp>Specifically, digital signature refers to catalog signature, which must meet WHQL certification\u003C\u002Fp>\u003Cp>Reference materials:\u003C\u002Fp>\u003Cp>https:\u002F\u002Fdocs.microsoft.com\u002Fzh-cn\u002Fwindows-hardware\u002Fdrivers\u002Finstall\u002Fwhql-release-signature\u003C\u002Fp>\u003Cp>There is an article introducing catalog signature: 'CAT File Digital Signature Usage Tips'\u003C\u002Fp>\u003Cp>Test system: Win8.1 x64\u003C\u002Fp>\u003Ch3>Configuration method:\u003C\u002Fh3>\u003Ch4>1. The operating system must meet the conditions:\u003C\u002Fh4>\u003Cp>Windows 8.1 or newer systems\u003C\u002Fp>\u003Ch4>2. Modify the registry\u003C\u002Fh4>\u003Cp>Registry location HKLM\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Image File Execution Options\\LSASS.exe, create a new DWORD entry AuditLevel with value 00000008\u003C\u002Fp>\u003Cp>The corresponding cmd command is as follows:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>REG ADD \"HKLM\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Image File Execution Options\\LSASS.exe\" \u002Fv \"AuditLevel\" \u002Ft REG_DWORD \u002Fd \"00000008\" \u002Ff\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Ch4>3. Restart the system\u003C\u002Fh4>\u003Ch2>0x03 Obtain monitoring results\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>View logs Event 3065 and Event 3066\u003C\u002Fp>\u003Cp>Event 3065: This event records that a code integrity check determined a process (typically lsass.exe) attempted to load a specific driver that did not meet the security requirements for shared sections. However, the image was allowed to load due to configured system policies.\u003C\u002Fp>\u003Cp>Event 3066: This event records that a code integrity check determined a process (typically lsass.exe) attempted to load a specific driver that did not meet Microsoft's signature level requirements. However, the image was allowed to load due to configured system policies.\u003C\u002Fp>\u003Cp>Location: Applications and Services Logs\\Microsoft\\Windows\\CodeIntegrity\u003C\u002Fp>\u003Cp>Can log non-compliant DLLs but did not prevent the DLL from loading, as shown in the figure below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fapi\u002Fmedia\u002Ffile\u002Fdocx_image_1770016179279_0_c9a46349fd-1.jpeg\">\u003C\u002Fp>\u003Cp>Query logs Event 3065 and Event 3066 via command line:\u003C\u002Fp>\u003Cp>Get log category list:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>wevtutil el &gt;1.txt\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>Found that the corresponding entry for CodeIntegrity is Microsoft-Windows-CodeIntegrity\u002FOperational\u003C\u002Fp>\u003Cp>Search for Event 3065 and Event 3066:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>wevtutil qe Microsoft-Windows-CodeIntegrity\u002FOperational \u002Frd:true \u002Ff:text \u002Fq:\"*[system\u002Feventid=3065 and 3066]\"\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>As shown in the figure below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fapi\u002Fmedia\u002Ffile\u002Fdocx_image_1770016181488_1_b4a5803f1f-1.jpeg\">\u003C\u002Fp>\u003Cp>\u003Cstrong>Supplement:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>Delete CodeIntegrity logs:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>wevtutil cl \"Microsoft-Windows-CodeIntegrity\u002FOperational\"\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Ch2>0x04 Supplement: An exploitation approach for Password Filter DLL—achieving DLL \"hiding\" using Long UNC filename spoofing\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>For specific hiding details, refer to the article \"Catalog Signature Forgery—Long UNC Filename Spoofing\"\u003C\u002Fp>\u003Ch3>1. Name the DLL in Long UNC filename format and save it under %windir%\\system32\\\u003C\u002Fh3>\u003Cp>The lsass.exe process loads scecli.dll by default, so choose to disguise the DLL as scecli.dll\u003C\u002Fp>\u003Cp>Command line:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>type Win32Project3.dll &gt; \"\\\\?\\C:\\windows\\system32\\scecli.dll \"\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>\u003Cstrong>Note:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>There is a space after the name scecli.dll\u003C\u002Fp>\u003Ch3>2. Obtain the short file name of the dll\u003C\u002Fh3>\u003Cp>Command line:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>dir \u002Fx scecli*.dll\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>Obtain the short file name SCECLI~1.DLL, as shown in the figure below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fapi\u002Fmedia\u002Ffile\u002Fdocx_image_1770016182675_2_79187055a4-1.jpeg\">\u003C\u002Fp>\u003Ch3>3. Modify the registry key value\u003C\u002Fh3>\u003Cp>Read the key value:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>REG QUERY \"HKLM\\SYSTEM\\CurrentControlSet\\Control\\Lsa\" \u002Fv \"Notification Packages\"\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>Add dll:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>REG ADD \"HKLM\\SYSTEM\\CurrentControlSet\\Control\\Lsa\" \u002Fv \"Notification Packages\" \u002Ft REG_MULTI_SZ \u002Fd \"scecli\\0SCECLI~1.DLL\" \u002Ff\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Ch3>4. Restart\u003C\u002Fh3>\u003Cp>Use Process Explorer to view the dlls loaded by the lsass process\u003C\u002Fp>\u003Cp>Shows loading two identical scecli.dlls, with specific attribute differences, as shown in the figure below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fapi\u002Fmedia\u002Ffile\u002Fdocx_image_1770016183938_3_50f8963324-1.jpeg\">\u003C\u002Fp>\u003Ch3>5. Detection\u003C\u002Fh3>\u003Cp>Event 3066 successfully detected, as shown in the figure below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fapi\u002Fmedia\u002Ffile\u002Fdocx_image_1770016185457_4_c9df7281f4-1.jpeg\">\u003C\u002Fp>\u003Ch2>0x05 Supplement\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>1. Adding a forged Microsoft Authenticode signature to the Password Filter DLL and modifying the certificate verification mechanism to make it effective still cannot bypass Additional LSA Protection monitoring, because the Password Filter DLL requires a legitimate catalog signature, not an Authenticode signature\u003C\u002Fp>\u003Cp>2. Creating a catalog signature for the Password Filter DLL and adding it to the system's security catalog database still cannot bypass Additional LSA Protection monitoring\u003C\u002Fp>\u003Ch2>0x06 Summary\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>This article introduces the method and detection effectiveness of configuring Additional LSA Protection to monitor Password Filter DLLs. If the Password Filter DLL does not have a legitimate catalog signature, the system can successfully detect it, but by default, it will not prevent loading\u003C\u002Fp>\u003C\u002Fbody>\u003C\u002Fhtml>",492,"Onedaysec",4,"published","2026-02-02T07:25:19.986Z",{"title":37,"description":14,"keywords":38,"ogImage":39,"canonicalUrl":39,"noIndex":40},"Configure LSA Protection & Monitor Password Filter DLL Security","LSA protection, Password Filter DLL, Windows security, DLL monitoring, registry configuration, CodeIntegrity logs, exploitation techniques, cybersecurity",null,false,[],{"docs":43,"hasNextPage":40},[44,45,46,4],983,982,981,{"title":39,"description":39,"image":39},"2026-07-24T15:37:10.434Z","2026-07-23T16:02:21.688Z","draft","2026-07-23T16:15:54.240Z"]