Windows Registry: Add Print Port Monitor DLL Persistence

Flags registry updates to Print Port Monitors that reference .dll components for potential startup persistence on Windows.

FreeReviewedSigma · Medium · v1
Product
windows
Category
registry_set
Author
frack113 (SigmaHQ), DRL 1.1
Published
2021-12-30
Updated
2026-07-30

ATT&CK techniques

Persistence → Priv Esc
  1. Recon

  2. Resource Dev

  3. Initial Access

  4. Execution

  5. Defense Evasion

  6. Cred Access

  7. Discovery

  8. Lateral Movement

  9. Collection

  10. C2

  11. Exfiltration

  12. Impact

What it detects

This rule identifies registry set activity that writes a port monitor entry under the Print Monitors control path where the Details value ends in .dll, indicating a DLL-backed startup component. This matters because loading an attacker-supplied DLL via port monitor startup can support persistence and potential privilege escalation. It relies on Windows registry set telemetry capturing TargetObject and Details values for the affected port monitor path, with optional exclusions to reduce known benign monitor entries.

Related detections6 linkedT1547.010 — drag to rearrange
SystemNightmare by GentilKiwi - External Printer Mapped - CVE-2021-1675 / CVE-2021-34527 (via security)
Malicious Print Spooler Privilege Escalation via Printer Added - CVE-2020-1048 (via powershell)
SystemNightmare by GentilKiwi - New External Device Added - CVE-2021-1675 / CVE-2021-34527 (via security)
Windows Process Creation: Suspicious secedit.exe Security Policy Export or Configuration
Registry Modification for UAC Bypass via Event Viewer Command Handler (Windows)
Windows Registry: RDP PortNumber changed from default 3389
Windows Registry: Add Print Port Monitor DLL Persistence
Pivot detection · T1547.010 · 6 related

Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.