Analytics BIOC Low

Suspicious Print System Remote Protocol usage by a process

A host which is trusted for unconstrained delegation initiated an SMB connection to a DC using the Print System Remote Protocol. An attacker can abuse such sessions for relay attacks.

Module:
Identity Analytics
Data source:
XDR Agent with eXtended Threat Hunting (XTH)
ATT&CK tactics: Credential Access (TA0006)
ATT&CK techniques: Forced Authentication (T1187)
Attacker's goals:

Elevate privileges from standard domain user to domain admin.

Investigative actions:

Check if the domain controller is patched or vulnerable to the attack. Check if the suspected account is compromised. Check if the source machine is trusted for unconstrained delegation and verify that the machine's configuration should stay that way. Follow actions by the account and if it performed a DCSync.

Test period:
N/A (single event)
Deduplication:
1 Day