Windows Registry Monitoring for Print Driver Path Names Used by Mimikatz
Detects registry TargetObject entries containing QMS 810 or mimikatz-related printer driver names under Windows print environments.
FreeUnreviewedSigmacriticalv1
windows-registry-monitoring-for-print-driver-path-names-used-by-mimikatz-ba6b9e43
title: Windows Registry Monitoring for Print Driver Path Names Used by Mimikatz
id: 52f885a9-f47b-45b3-98cc-3647060982e0
status: test
description: This rule flags Windows registry events whose TargetObject contains specific Print Environment driver paths associated with mimikatz and a QMS 810 driver name. Attackers may leverage these embedded printer-related strings to execute or stage actions via Windows print subsystem interactions. It relies on registry event telemetry, specifically the TargetObject substring values present in Control\Print Environments driver locations and known printer-name markers.
references:
- https://github.com/gentilkiwi/mimikatz/commit/c21276072b3f2a47a21e215a46962a17d54b3760
- https://www.lexjansen.com/sesug/1993/SESUG93035.pdf
- https://learn.microsoft.com/en-us/openspecs/windows_protocols/ms-rprn/4464eaf0-f34f-40d5-b970-736437a21913
- https://nvd.nist.gov/vuln/detail/cve-2021-1675
- https://nvd.nist.gov/vuln/detail/cve-2021-34527
- https://github.com/SigmaHQ/sigma/blob/master/rules-emerging-threats/2021/Exploits/CVE-2021-1675/registry_event_cve_2021_1675_mimikatz_printernightmare_drivers.yml
author: Markus Neis, @markus_neis, Florian Roth, Huntrule Team
date: 2021-07-04
modified: 2023-06-12
tags:
- attack.execution
- attack.t1204
- cve.2021-1675
- cve.2021-34527
- detection.emerging-threats
logsource:
product: windows
category: registry_event
detection:
selection:
TargetObject|contains:
- \Control\Print\Environments\Windows x64\Drivers\Version-3\QMS 810\
- \Control\Print\Environments\Windows x64\Drivers\Version-3\mimikatz
selection_alt:
TargetObject|contains|all:
- legitprinter
- \Control\Print\Environments\Windows
selection_print:
TargetObject|contains:
- \Control\Print\Environments
- \CurrentVersion\Print\Printers
selection_kiwi:
TargetObject|contains:
- Gentil Kiwi
- mimikatz printer
- Kiwi Legit Printer
condition: selection or selection_alt or (selection_print and selection_kiwi)
falsepositives:
- Legitimate installation of printer driver QMS 810, Texas Instruments microLaser printer (unlikely)
level: critical
license: DRL-1.1
related:
- id: ba6b9e43-1d45-4d3c-a504-1043a64c8469
type: derived
What it detects
This rule flags Windows registry events whose TargetObject contains specific Print Environment driver paths associated with mimikatz and a QMS 810 driver name. Attackers may leverage these embedded printer-related strings to execute or stage actions via Windows print subsystem interactions. It relies on registry event telemetry, specifically the TargetObject substring values present in Control\Print Environments driver locations and known printer-name markers.
Known false positives
- Legitimate installation of printer driver QMS 810, Texas Instruments microLaser printer (unlikely)
Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.