Windows Print Spooler Exploitation Indicators: UNIDRV.DLL and mimispool Driver Loads (Event ID 316)

Flags Windows Print Spooler Event ID 316 entries containing UNIDRV/mimispool-related keywords indicative of CVE-2021-1675 exploitation.

FreeReviewedSigma · Critical · v5
Product
windows
Service
printservice-operational
Author
Florian Roth (Nextron Systems) (SigmaHQ), DRL 1.1
Published
2021-07-01
Updated
2026-07-31

ATT&CK techniques

Execution
  1. Recon

  2. Resource Dev

  3. Initial Access

  4. Persistence

  5. Priv Esc

  6. Defense Evasion

  7. Cred Access

  8. Discovery

  9. Lateral Movement

  10. Collection

  11. C2

  12. Exfiltration

  13. Impact

What it detects

This rule identifies likely successful exploitation attempts of the Windows Print Spooler by matching specific driver-load activity in the PrintServiceOperational log. The behavior matters because attackers abusing the spooler can execute malicious code via loaded components and related payload naming. It relies on Event ID 316 and the presence of targeted strings (including UNIDRV.DLL and mimispool) within the event data.

Related detections6 linkedT1569 — drag to rearrange
Obfuscated Massive Service Failures - Tchopper (via system)
Malicious Massive Remote Service Creation via Named Pipes - TChopper, CME (via security)
Malicious Massive Remote Service Creation via Named Pipes - Tchopper (via security)
KrbRelayUp Service Installation - Native (via system)
Windows Print Spooler Plugin Load Errors Indicative of CVE-2021-1675 Exploitation
Windows PsExec Execution Triggered by psexec.exe Process Creation
Windows Print Spooler Exploitation Indicators: UNIDRV.DLL and mimispool Driver Loads (Event ID 316)
Pivot detection · T1569 · 6 related

Changelog

v5
  1. v5
    Candidate ingested via manual entry.2026-07-31
  2. v4
    Candidate ingested via manual entry.2026-07-31
  3. v3
    Candidate ingested via manual entry.2026-07-31
  4. v2
    Candidate ingested via manual entry.2026-07-31
  5. v1
    No changelog recorded for this version.2026-07-30

Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.