CAPEC 579 Replace Winlogon Helper DLL

Draft Detailed Unknown Risk

Description

Winlogon is a part of Windows that performs logon actions. In Windows systems prior to Windows Vista, a registry key can be modified that causes Winlogon to load a DLL on startup. Adversaries may take advantage of this feature to load adversarial code at startup.

Mitigations

1

Consequences

Relationships

Related ATT&CK Techniques

1