Potential PrintNightmare Exploitation Attempt

 Original Source: [Sigma source]
Title: Potential PrintNightmare Exploitation Attempt
Status: test
Description:Detect DLL deletions from Spooler Service driver folder. This might be a potential exploitation attempt of CVE-2021-1675
References:
  -https://web.archive.org/web/20210629055600/https://github.com/hhlxf/PrintNightmare/
  -https://github.com/cube0x0/CVE-2021-1675
Author: Bhabesh Raj
Date: 2021-07-01
modified:2023-02-17
Tags:
  • -'attack.persistence'
  • -'attack.defense-evasion'
  • -'attack.privilege-escalation'
  • -'attack.t1574'
  • -'cve.2021-1675'
Logsource:
  • category: file_delete
  • product: windows
Detection:
  selection:
    Image|endswith: '\spoolsv.exe'
    TargetFilename|contains: 'C:\Windows\System32\spool\drivers\x64\3\'
  condition:selection
Falsepositives:
  -Unknown
Level: high