Windows Spooler Service Suspicious Binary Load

 Original Source: [Sigma source]
Title: Windows Spooler Service Suspicious Binary Load
Status: test
Description:Detect DLL Load from Spooler Service backup folder
References:
  -https://web.archive.org/web/20210629055600/https://github.com/hhlxf/PrintNightmare/
  -https://github.com/ly4k/SpoolFool
Author: FPT.EagleEye, Thomas Patzke (improvements)
Date: 2021-06-29
modified:2022-06-02
Tags:
  • -'attack.persistence'
  • -'attack.defense-evasion'
  • -'attack.privilege-escalation'
  • -'attack.t1574'
  • -'cve.2021-1675'
  • -'cve.2021-34527'
Logsource:
  • category: image_load
  • product: windows
Detection:
  selection:
    Image|endswith: '\spoolsv.exe'
    ImageLoaded|contains:
      -'\Windows\System32\spool\drivers\x64\3\'
      -'\Windows\System32\spool\drivers\x64\4\'

    ImageLoaded|endswith: '.dll'
  condition:selection
Falsepositives:
  -Loading of legitimate driver
Level: informational