DCERPC SMB Spoolss Named Pipe

 Original Source: [Sigma source]
Title: DCERPC SMB Spoolss Named Pipe
Status: test
Description:Detects the use of the spoolss named pipe over SMB. This can be used to trigger the authentication via NTLM of any machine that has the spoolservice enabled.
References:
  -https://posts.specterops.io/hunting-in-active-directory-unconstrained-delegation-forests-trusts-71f2b33688e1
  -https://dirkjanm.io/a-different-way-of-abusing-zerologon/
  -https://twitter.com/_dirkjan/status/1309214379003588608
Author: OTR (Open Threat Research)
Date: 2018-11-28
modified:2022-08-11
Tags:
  • -'attack.lateral-movement'
  • -'attack.t1021.002'
Logsource:
  • product: windows
  • service: security
Detection:
  selection:
    EventID: '5145'
    ShareName: '\\\\\*\\IPC$'
    RelativeTargetName: 'spoolss'
  condition:selection
Falsepositives:
  -Domain Controllers acting as printer servers too? :)
Level: medium