BIOC
Low
✕
Suspicious printer driver installation
A suspicious process installed a generic printer driver. This may be a sign of CVE-2020-1048, in which an attacker attempts to overwrite a file on the OS.
- Module:
- Platform Analytics
- Agent event type:
- Registry
- Category:
- Privilege Escalation
- Status:
- Enabled
ATT&CK tactics: Privilege Escalation (TA0004) Persistence (TA0003)
ATT&CK techniques: Boot or Logon Autostart Execution: Port Monitors (T1547.010)
Indicator:
Registry registry data = Generic / Text Only AND registry key name = *windows nt\currentversion\print\printers* AND action type = set_registry_value Process initiator signature = Unsigned , Invalid Signature Host host os = windows
Preventable: yes