Port Monitors

T1547.010

Sub-technique of T1547 Boot or Logon Autostart Execution.View on attack.mitre.org

About this technique

Adversaries may use port monitors to run an adversary supplied DLL during system boot for persistence or privilege escalation. A port monitor can be set through the AddMonitor API call to set a DLL to be loaded at startup. This DLL can be located in C:\Windows\System32 and will be loaded and run by the print spooler service, `spoolsv.exe`, under SYSTEM level permissions on boot.

Alternatively, an arbitrary DLL can be loaded if permissions allow writing a fully-qualified pathname for that DLL to the `Driver` value of an existing or new arbitrarily named subkey of HKLM\SYSTEM\CurrentControlSet\Control\Print\Monitors. The Registry key contains entries for the following:

* Local Port
* Standard TCP/IP Port
* USB Monitor
* WSD Port

Detection rules5

Rules on DetectionCode tagged with T1547.010.

Sigma4

RuleLevelLog source
Bypass UAC Using Event Viewerhighwindows / registry_set
Default RDP Port Changed to Non Standard Porthighwindows / registry_set
Add Port Monitor Persistence in Registrymediumwindows / registry_set
Potential Suspicious Activity Using SeCEditmediumwindows / process_creation

Splunk1

RuleTypeRiskData source
Monitor Registry Keys for Print MonitorsTTPNULLSysmon EventID 13

Groups0

None recorded.

Software0

None recorded.

Campaigns0

None recorded.

Procedure examples0

No procedure examples are recorded for this technique.

References2

  1. AddMonitor Open source
    Microsoft. (n.d.). AddMonitor function. Retrieved September 12, 2024.
  2. Bloxham Open source
    Bloxham, B. (n.d.). Getting Windows to Play with Itself [PowerPoint slides]. Retrieved November 12, 2014.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.