Elastic high stable eql
Suspicious Print Spooler Point and Print DLL
Detects attempts to exploit a privilege escalation vulnerability (CVE-2020-1030) related to the print spooler service. Exploitation involves chaining multiple primitives to load an arbitrary DLL into the print spooler process running as SYSTEM.
Detection Logic
sequence by host.id with maxspan=30s
[registry where host.os.type == "windows" and
registry.value : "SpoolDirectory" and
registry.path : "*\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Print\\Printers\\*\\SpoolDirectory" and
registry.data.strings : "C:\\Windows\\System32\\spool\\drivers\\x64\\4"]
[registry where host.os.type == "windows" and
registry.value : "Module" and
registry.path : "*\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Print\\Printers\\*\\CopyFiles\\Payload\\Module" and
registry.data.strings : "C:\\Windows\\System32\\spool\\drivers\\x64\\4\\*"] Field Validations
Loading…
Comments (0)
Loading comments...