Analytics BIOC
Low
✕
Suspicious Print System Remote Protocol usage by a process
A host which is trusted for unconstrained delegation initiated an SMB connection to a DC using the Print System Remote Protocol. An attacker can abuse such sessions for relay attacks.
- Module:
- Identity Analytics
- Data source:
- XDR Agent with eXtended Threat Hunting (XTH)
ATT&CK tactics: Credential Access (TA0006)
ATT&CK techniques: Forced Authentication (T1187)
Attacker's goals:
Elevate privileges from standard domain user to domain admin.
Investigative actions:
Check if the domain controller is patched or vulnerable to the attack. Check if the suspected account is compromised. Check if the source machine is trusted for unconstrained delegation and verify that the machine's configuration should stay that way. Follow actions by the account and if it performed a DCSync.
- Test period:
- N/A (single event)
- Deduplication:
- 1 Day