BIOC
Medium
✕
Suspicious printer port creation via Registry
An attacker may create a print job that prints to a file, overwriting any file on the OS (CVE-2020-1048).
- Module:
- Platform Analytics
- Agent event type:
- Registry
- Category:
- Privilege Escalation
- Status:
- Enabled
ATT&CK tactics: Privilege Escalation (TA0004) Persistence (TA0003)
ATT&CK techniques: Boot or Logon Autostart Execution: Port Monitors (T1547.010)
Indicator:
Registry registry value name = *.exe , *.dll , *.bat , *.com , *.cmd , *.ps1 , *.hta , *.vba , *.vbs , *.vbe , *.js AND registry key name = *\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Ports AND action type = set_registry_value Host host os = windows
Preventable: yes