Windows Registry Monitoring for Print Driver Path Names Used by Mimikatz

Detects registry TargetObject entries containing QMS 810 or mimikatz-related printer driver names under Windows print environments.

FreeUnreviewedSigmacriticalv1
title: Windows Registry Monitoring for Print Driver Path Names Used by Mimikatz
id: 52f885a9-f47b-45b3-98cc-3647060982e0
status: test
description: This rule flags Windows registry events whose TargetObject contains specific Print Environment driver paths associated with mimikatz and a QMS 810 driver name. Attackers may leverage these embedded printer-related strings to execute or stage actions via Windows print subsystem interactions. It relies on registry event telemetry, specifically the TargetObject substring values present in Control\Print Environments driver locations and known printer-name markers.
references:
  - https://github.com/gentilkiwi/mimikatz/commit/c21276072b3f2a47a21e215a46962a17d54b3760
  - https://www.lexjansen.com/sesug/1993/SESUG93035.pdf
  - https://learn.microsoft.com/en-us/openspecs/windows_protocols/ms-rprn/4464eaf0-f34f-40d5-b970-736437a21913
  - https://nvd.nist.gov/vuln/detail/cve-2021-1675
  - https://nvd.nist.gov/vuln/detail/cve-2021-34527
  - https://github.com/SigmaHQ/sigma/blob/master/rules-emerging-threats/2021/Exploits/CVE-2021-1675/registry_event_cve_2021_1675_mimikatz_printernightmare_drivers.yml
author: Markus Neis, @markus_neis, Florian Roth, Huntrule Team
date: 2021-07-04
modified: 2023-06-12
tags:
  - attack.execution
  - attack.t1204
  - cve.2021-1675
  - cve.2021-34527
  - detection.emerging-threats
logsource:
  product: windows
  category: registry_event
detection:
  selection:
    TargetObject|contains:
      - \Control\Print\Environments\Windows x64\Drivers\Version-3\QMS 810\
      - \Control\Print\Environments\Windows x64\Drivers\Version-3\mimikatz
  selection_alt:
    TargetObject|contains|all:
      - legitprinter
      - \Control\Print\Environments\Windows
  selection_print:
    TargetObject|contains:
      - \Control\Print\Environments
      - \CurrentVersion\Print\Printers
  selection_kiwi:
    TargetObject|contains:
      - Gentil Kiwi
      - mimikatz printer
      - Kiwi Legit Printer
  condition: selection or selection_alt or (selection_print and selection_kiwi)
falsepositives:
  - Legitimate installation of printer driver QMS 810, Texas Instruments microLaser printer (unlikely)
level: critical
license: DRL-1.1
related:
  - id: ba6b9e43-1d45-4d3c-a504-1043a64c8469
    type: derived

What it detects

This rule flags Windows registry events whose TargetObject contains specific Print Environment driver paths associated with mimikatz and a QMS 810 driver name. Attackers may leverage these embedded printer-related strings to execute or stage actions via Windows print subsystem interactions. It relies on registry event telemetry, specifically the TargetObject substring values present in Control\Print Environments driver locations and known printer-name markers.

Known false positives

  • Legitimate installation of printer driver QMS 810, Texas Instruments microLaser printer (unlikely)

Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.