Threaticon
Toggle sidebar

You're viewing a limited, public preview. Log in for full access.

Log in User Guide
Log in Get started
Detection Strategies DET0204 — Detection Strategy for T1547.010 – Port Monitor DLL Persistence via spoolsv.exe (Windows)
DET0204

Detection Strategy for T1547.010 – Port Monitor DLL Persistence via spoolsv.exe (Windows)

1 analytic(s) · 1 technique(s) detected

Analytics

1
AN0580 Analytic 0580
Windows

Detects suspicious registry modifications under `HKLM\SYSTEM\CurrentControlSet\Control\Print\Monitors\*\Driver`, DLL loads by `spoolsv.exe` of non-standard or unsigned modules, and abnormal usage of the `AddMonitor` API by non-installation processes. This pattern often indicates an attempt to persist a malicious DLL via the print monitor mechanism, particularly when correlated with creation of files in `C:\Windows\System32` not tied to known patches or installations.

WinEventLog:Sysmon EventCode=1 WinEventLog:Sysmon EventCode=7 WinEventLog:Sysmon EventCode=13 WinEventLog:Sysmon EventCode=11 WinEventLog:Application API call to AddMonitor invoked by non-installer process
[TargetDLLDirectory] Expected directory path for legitimate monitor DLLs (e.g., C:\Windows\System32)
[SignedImageValidation] Enable/disable signature validation on DLLs loaded by spoolsv.exe
[UserContextScope] Define whether only SYSTEM/user installs are expected to make changes to the port monitor registry keys
[TimeWindow] Timeframe between registry modification and subsequent spoolsv.exe DLL load
[AddMonitorCallContext] Filter on calling process of AddMonitor API to detect anomalies outside installer/updater

Detected Techniques

1

Details

MITRE ID
DET0204
STIX ID
x-mitre-detection-strategy--a62dbd10-5b61-489c-a465-8f792792778e
Analytics
1
Techniques Detected
1
By Tactic
Persistence
1
Leaving Threaticon

This link opens an external site that isn't part of the platform.