LSA Authentication/Security Package Registration for Credential Capture
Detects the modification or creation of registry values under the Windows Local Security Authority (LSA) configuration key, specifically targeting the 'Authentication Packages' or 'Security Packages' values. Adversaries often use these registry locations to inject custom DLLs that are loaded by the LSA process (lsass.exe) at system boot for persistence or credential dumping.
Microsoft Sentinel (KQL)

