Elastic low stable eql
Suspicious Print Spooler SPL File Created
Detects attempts to exploit privilege escalation vulnerabilities related to the Print Spooler service including CVE-2020-1048 and CVE-2020-1337.
Detection Logic
file where host.os.type == "windows" and event.type != "deletion" and
file.extension : "spl" and
file.path : "?:\\Windows\\System32\\spool\\PRINTERS\\*" and
not process.name : ("spoolsv.exe",
"printfilterpipelinesvc.exe",
"PrintIsolationHost.exe",
"splwow64.exe",
"msiexec.exe",
"poqexec.exe",
"System") and
not user.id : "S-1-5-18" and
not process.executable :
("?:\\Windows\\System32\\mmc.exe",
"\\Device\\Mup\\*.exe",
"?:\\Windows\\System32\\svchost.exe",
"?:\\Windows\\System32\\mmc.exe",
"?:\\Windows\\System32\\printui.exe",
"?:\\Windows\\System32\\mstsc.exe",
"?:\\Windows\\System32\\spool\\*.exe",
"?:\\Program Files\\*.exe",
"?:\\Program Files (x86)\\*.exe",
"?:\\PROGRA~1\\*.exe",
"?:\\PROGRA~2\\*.exe",
"?:\\Windows\\System32\\rundll32.exe") Field Validations
Loading…
Comments (0)
Loading comments...