BIOC Low

Suspicious printer driver installation

A suspicious process installed a generic printer driver. This may be a sign of CVE-2020-1048, in which an attacker attempts to overwrite a file on the OS.

Module:
Platform Analytics
Agent event type:
Registry
Category:
Privilege Escalation
Status:
Enabled
ATT&CK tactics: Privilege Escalation (TA0004) Persistence (TA0003)
ATT&CK techniques: Boot or Logon Autostart Execution: Port Monitors (T1547.010)
Indicator:

Registry registry data = Generic / Text Only AND registry key name = *windows nt\currentversion\print\printers* AND action type = set_registry_value Process initiator signature = Unsigned , Invalid Signature Host host os = windows

Preventable: yes