Windows Rundll32 Calls DavSetCookie for NTLM Coercion via Spoolss/Srvsvc

Detects rundll32.exe launching davclnt.dll DavSetCookie with HTTP and spoolss/srvsvc pipe parameters associated with NTLM coercion.

FreeReviewedSigma · High · v1
Product
windows
Category
process_creation
Author
Elastic (idea), Tobias Michalski (Nextron Systems) (SigmaHQ), DRL 1.1
Published
2022-05-04
Updated
2026-07-30

ATT&CK techniques

Cred Access
  1. Recon

  2. Resource Dev

  3. Initial Access

  4. Execution

  5. Persistence

  6. Priv Esc

  7. Defense Evasion

  8. Discovery

  9. Lateral Movement

  10. Collection

  11. C2

  12. Exfiltration

  13. Impact

What it detects

This rule flags process execution of rundll32.exe invoking davclnt.dll,DavSetCookie with HTTP-related parameters tied to spoolss and srvsvc named-pipe targeting. This behavior can be used to coerce an NTLM authentication attempt through the Printer Spooler/SMB print service pathway, which may enable credential relay and privilege escalation. It relies on process creation telemetry, matching rundll32 image details and specific command-line substrings used in the invocation.

Related detections4 linkedT1212 — drag to rearrange
Apache Guacamole Linux: Two-User Session Presence Anomaly
Windows Process Creation alerts on GALLIUM-associated hash IOCs
Windows Audit-CVE: User Applications Writing CveEventWrite Events (Event ID 1)
Windows Kerberos TGT Issue Operations Failures (Event IDs 675/4768/4769/4771)
Windows Rundll32 Calls DavSetCookie for NTLM Coercion via Spoolss/Srvsvc
Pivot detection · T1212 · 4 related

Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.