Windows Registry: Add Print Port Monitor DLL Persistence

Flags registry updates to Print Port Monitors that reference .dll components for potential startup persistence on Windows.

FreeUnreviewedSigmamediumv1
title: "Windows Registry: Add Print Port Monitor DLL Persistence"
id: 4befdea0-3423-49c3-ab11-282f00621f5e
status: test
description: This rule identifies registry set activity that writes a port monitor entry under the Print Monitors control path where the Details value ends in .dll, indicating a DLL-backed startup component. This matters because loading an attacker-supplied DLL via port monitor startup can support persistence and potential privilege escalation. It relies on Windows registry set telemetry capturing TargetObject and Details values for the affected port monitor path, with optional exclusions to reduce known benign monitor entries.
references:
  - https://github.com/redcanaryco/atomic-red-team/blob/f339e7da7d05f6057fdfcdd3742bfcf365fee2a9/atomics/T1547.010/T1547.010.md
  - https://github.com/SigmaHQ/sigma/blob/master/rules/windows/registry/registry_set/registry_set_add_port_monitor.yml
author: frack113, Huntrule Team
date: 2021-12-30
modified: 2024-03-25
tags:
  - attack.privilege-escalation
  - attack.persistence
  - attack.t1547.010
logsource:
  category: registry_set
  product: windows
detection:
  selection:
    TargetObject|contains: \Control\Print\Monitors\
    Details|endswith: .dll
  filter_optional_cutepdf:
    Image: C:\Windows\System32\spoolsv.exe
    TargetObject|contains: \Control\Print\Monitors\CutePDF Writer Monitor v4.0\Driver
    Details: cpwmon64_v40.dll
    User|contains:
      - AUTHORI
      - AUTORI
  filter_optional_monvnc:
    TargetObject|contains: \Control\Print\Monitors\MONVNC\Driver
  filter_optional_vnc:
    TargetObject|contains|all:
      - Control\Print\Environments\
      - \Drivers\
      - \VNC Printer
  condition: selection and not 1 of filter_optional_*
falsepositives:
  - Unknown
level: medium
regression_tests_path: regression_data/rules/windows/registry/registry_set/registry_set_add_port_monitor/info.yml
simulation:
  - type: atomic-red-team
    name: Add Port Monitor persistence in Registry
    technique: T1547.010
    atomic_guid: d34ef297-f178-4462-871e-9ce618d44e50
license: DRL-1.1
related:
  - id: 944e8941-f6f6-4ee8-ac05-1c224e923c0e
    type: derived

What it detects

This rule identifies registry set activity that writes a port monitor entry under the Print Monitors control path where the Details value ends in .dll, indicating a DLL-backed startup component. This matters because loading an attacker-supplied DLL via port monitor startup can support persistence and potential privilege escalation. It relies on Windows registry set telemetry capturing TargetObject and Details values for the affected port monitor path, with optional exclusions to reduce known benign monitor entries.

Known false positives

  • Unknown

Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.