T1556: Unsigned/Untrusted LSA Password Filter, SSP-AP or Network Provider

Detects unauthorized modifications to critical authentication-related configuration files and registry keys. Specifically monitors changes to LSA security packages and notification packages on Windows systems, as well as PAM configuration file modifications on Linux systems, when performed by unsigned or untrusted processes outside of known installer activity.