Skip to content

Subject Interface Package

Data Type: subject_interface_package
Python Parser: RegSIPP

Description

Each row is a Subject Interface Package registration used by Windows trust services, with GUID, descriptive name, implementing DLL, entry-point function, and registry provenance. Use it to hunt trust-provider tampering by comparing DLL paths and functions with a known-good baseline. Registration alone does not prove the package loaded or that its output was trustworthy.

Timeline

Timeline Field Data Field
Related User key_security.owner_sid
Description name
Additional Description dll
function_name
guid

Fields

Output Name Data Type Description
name String human‑readable name of the Subject Interface Package (SIP) identified by the GUID
dll String filesystem path to the DLL that implements the SIP
function_name String entry‑point function name within the DLL used for SIP verification
guid String GUID uniquely identifying the Subject Interface Package
key_path String full registry key name
key_modif_time DateTime last modification timestamp of the registry key
key_security Object
key_security.owner_sid String SID of the user that owns the registry key
key_security.group_sid String SID of the group that owns the registry key
key_security.control_flags[] Array[String] security descriptor control flags for the key
key_security.sacl_aces[] Array[Object]
key_security.sacl_aces[].ace_type String type of ACE (e.g., allow, deny)
key_security.sacl_aces[].ace_flags[] Array[String] ACE flags that modify inheritance or behavior
key_security.sacl_aces[].rights[] Array[String] permissions granted or denied by the ACE
key_security.sacl_aces[].account_sid String SID of the account the ACE applies to
key_security.sacl_aces[].ace_size Int declared ACE size in bytes
key_security.sacl_aces[].object_type_guid String GUID identifying the object type governed by the ACE
key_security.sacl_aces[].inherited_object_type_guid String GUID identifying the inherited object type governed by the ACE
key_security.sacl_aces[].raw_hex String raw ACE bytes preserved as hexadecimal
key_security.dacl_aces[] Array[Object]
key_security.dacl_aces[].ace_type String type of ACE (e.g., allow, deny)
key_security.dacl_aces[].ace_flags[] Array[String] ACE flags that modify inheritance or behavior
key_security.dacl_aces[].rights[] Array[String] permissions granted or denied by the ACE
key_security.dacl_aces[].account_sid String SID of the account the ACE applies to
key_security.dacl_aces[].ace_size Int declared ACE size in bytes
key_security.dacl_aces[].object_type_guid String GUID identifying the object type governed by the ACE
key_security.dacl_aces[].inherited_object_type_guid String GUID identifying the inherited object type governed by the ACE
key_security.dacl_aces[].raw_hex String raw ACE bytes preserved as hexadecimal