heroui logo

Potential Port Monitor or Print Processor Registration Abuse

Elastic Detection Rules

View Source
Summary
This detection rule is designed to identify unauthorized modifications to the Windows Registry related to port monitors and print processors, which adversaries may exploit for malicious purposes. Specifically, adversaries can abuse these components to register malicious Dynamic Link Libraries (DLLs) that execute with SYSTEM privileges during system boot, potentially allowing for privilege escalation and persistence. The rule looks for changes in specific registry paths associated with printing services, filtering out changes made by the SYSTEM user to focus on alterations that may indicate malicious activity. This is crucial for monitoring any unauthorized attempts to alter trusted system-level components that could compromise the integrity of the Windows operating system.
Categories
  • Endpoint
  • Windows
Data Sources
  • Windows Registry
  • Application Log
ATT&CK Techniques
  • T1547
  • T1547.010
  • T1547.012
Created: 2021-01-21