title: PrintNightmare Powershell Exploitation id: 6d3f1399-a81c-4409-aff3-1ecfe9330baf status: test description: Detects Commandlet name for PrintNightmare exploitation. references: - https://github.com/calebstewart/CVE-2021-1675 author: Max Altgelt, Tobias Michalski date: 2021/08/09 modified: 2021/10/16 tags: - attack.privilege_escalation - attack.t1548 logsource: product: windows category: ps_script definition: Script Block Logging must be enabled detection: selection: ScriptBlockText|contains: 'Invoke-Nightmare' condition: selection falsepositives: - Unknown level: high