Merge pull request #1596 from d4rk-d4nph3/master

Added new observed path for Image Load in PrintNightmare
This commit is contained in:
Florian Roth
2021-07-01 09:44:52 +02:00
committed by GitHub
@@ -6,6 +6,7 @@ references:
- https://github.com/hhlxf/PrintNightmare
author: FPT.EagleEye
date: 2021/06/29
modified: 2021/07/01
tags:
- attack.persistence
- attack.defense_evasion
@@ -20,7 +21,8 @@ detection:
Image|endswith:
- 'spoolsv.exe'
ImageLoaded:
- 'Windows\System32\spool\drivers\x64\3\old\*.dll'
- 'C:\Windows\System32\spool\drivers\x64\3\old\*.dll'
- 'C:\Windows\System32\spool\drivers\x64\3\*.dll'
condition: selection
falsepositives:
- Possible. Requires further testing.