SMB Spoolss Name Piped Usage

 Original Source: [Sigma source]
Title: SMB Spoolss Name Piped Usage
Status: test
Description:Detects the use of the spoolss named pipe over SMB. This can be used to trigger the authentication via NTLM of any machine that has the spoolservice enabled.
References:
  -https://posts.specterops.io/hunting-in-active-directory-unconstrained-delegation-forests-trusts-71f2b33688e1
  -https://dirkjanm.io/a-different-way-of-abusing-zerologon/
  -https://twitter.com/_dirkjan/status/1309214379003588608
Author: OTR (Open Threat Research), @neu5ron
Date: 2018-11-28
modified:2022-10-09
Tags:
  • -'attack.lateral-movement'
  • -'attack.t1021.002'
Logsource:
  • product: zeek
  • service: smb_files
Detection:
  selection:
    path|endswith: 'IPC$'
    name: 'spoolss'
  condition:selection
Falsepositives:
  -Domain Controllers that are sometimes, commonly although should not be, acting as printer servers too
Level: medium