Bidda Sovereign Intelligence · 10,085 Verified Nodes · 39 Sovereign Pillars

MITRE ATT&CK T1556.008: Network Provider DLL (Enterprise Tactic TA0006 - Credential Access / TA0005 - Defense Evasion / TA0003 - Persistence)

MITRE ATT&CK T1556.008 (Network Provider DLL) is an Enterprise Credential Access and Defense Evasion and Persistence sub-technique of T1556 (Modify…

What MITRE ATT&CK T1556.008: Network Provider DLL (Enterprise Tactic TA0006 - Credential Access / TA0005 - Defense Evasion / TA0003 - Persistence) requires

MITRE ATT&CK T1556.008 (Network Provider DLL) is an Enterprise Credential Access and Defense Evasion and Persistence sub-technique of T1556 (Modify Authentication Process). Adversaries may register malicious network provider dynamic link libraries (DLLs) to capture cleartext user credentials during the authentication process. Network provider DLLs allow Windows to interface with specific network protocols and can also support add-on credential management functions. During the logon process, Winlogon (the interactive logon module) sends credentials to the local mpnotify.exe process via RPC. Affected platforms: Windows. MITRE-documented mitigations include M1024 Restrict Registry Permissions, M1047 Audit, M1028 Operating System Configuration. The Center for Threat-Informed Defense maps this technique to NIST SP 800-53 Rev 5 controls AC-02, AC-03, AC-05, AC-06, AC-07, AC-20, CA-07, CM-02.

Pillar: Cybersecurity · Authority: MITRE Corporation · Version: 1.0.0 · Last updated:

Primary source: https://attack.mitre.org/techniques/T1556/008/

SHA-256 integrity: 460ad189e1ce74baa9557a1736f841223828e7015cab79941b76aa21830c201d

Primary Citations — 7 traced to source

  • MITRE ATT&CK Technique T1556.008: Network Provider DLL (https://attack.mitre.org/techniques/T1556/008/)
  • MITRE ATT&CK Tactic TA0006: Credential Access (https://attack.mitre.org/tactics/TA0006/)

+ 5 more citations (full bibliography, deterministic workflow, actionable schema and crosswalks) included in the vault unlock — $0.01 via Skyfire / L402 / Direct Base USDC.

Access

⚠ Important: Human Verification Required

Bidda compliance nodes are reference intelligence, not legal advice. Every node must be reviewed by a qualified compliance professional or legal counsel before implementation in any enterprise workflow, regulated system, or compliance programme. See bidda.com/disclaimer for full terms.