Sub-technique of T1547 Boot or Logon Autostart Execution.View on attack.mitre.org
Adversaries may use port monitors to run an adversary supplied DLL during system boot for persistence or privilege escalation. A port monitor can be set through the AddMonitor API call to set a DLL to be loaded at startup. This DLL can be located in C:\Windows\System32 and will be loaded and run by the print spooler service, `spoolsv.exe`, under SYSTEM level permissions on boot.
Alternatively, an arbitrary DLL can be loaded if permissions allow writing a fully-qualified pathname for that DLL to the `Driver` value of an existing or new arbitrarily named subkey of HKLM\SYSTEM\CurrentControlSet\Control\Print\Monitors. The Registry key contains entries for the following:
* Local Port
* Standard TCP/IP Port
* USB Monitor
* WSD Port
Rules on DetectionCode tagged with T1547.010.
| Rule | Level | Log source |
|---|---|---|
| Bypass UAC Using Event Viewer | high | windows / registry_set |
| Default RDP Port Changed to Non Standard Port | high | windows / registry_set |
| Add Port Monitor Persistence in Registry | medium | windows / registry_set |
| Potential Suspicious Activity Using SeCEdit | medium | windows / process_creation |
| Rule | Type | Risk | Data source |
|---|---|---|---|
| Monitor Registry Keys for Print Monitors | TTP | NULL | Sysmon EventID 13 |
None recorded.
None recorded.
None recorded.
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.