PrinterNightmare Mimikatz Driver Name

 Original Source: [Sigma source]
Title: PrinterNightmare Mimikatz Driver Name
Status: test
Description:Detects static QMS 810 and mimikatz driver name used by Mimikatz as exploited in CVE-2021-1675 and CVE-2021-34527
References:
  -https://github.com/gentilkiwi/mimikatz/commit/c21276072b3f2a47a21e215a46962a17d54b3760
  -https://www.lexjansen.com/sesug/1993/SESUG93035.pdf
  -https://learn.microsoft.com/en-us/openspecs/windows_protocols/ms-rprn/4464eaf0-f34f-40d5-b970-736437a21913
  -https://nvd.nist.gov/vuln/detail/cve-2021-1675
  -https://nvd.nist.gov/vuln/detail/cve-2021-34527
Author: Markus Neis, @markus_neis, Florian Roth
Date: 2021-07-04
modified:2023-06-12
Tags:
  • -'attack.execution'
  • -'attack.t1204'
  • -'cve.2021-1675'
  • -'cve.2021-34527'
Logsource:
  • product: windows
  • category: registry_event
Detection:
  selection:
    TargetObject|contains:
      -'\Control\Print\Environments\Windows x64\Drivers\Version-3\QMS 810\'
      -'\Control\Print\Environments\Windows x64\Drivers\Version-3\mimikatz'

  selection_alt:
    TargetObject|contains|all:
      -'legitprinter'
      -'\Control\Print\Environments\Windows'

  selection_print:
    TargetObject|contains:
      -'\Control\Print\Environments'
      -'\CurrentVersion\Print\Printers'

  selection_kiwi:
    TargetObject|contains:
      -'Gentil Kiwi'
      -'mimikatz printer'
      -'Kiwi Legit Printer'

  condition:selection or selection_alt or (selection_print and selection_kiwi)
Falsepositives:
  -Legitimate installation of printer driver QMS 810, Texas Instruments microLaser printer (unlikely)
Level: critical