Zeek DCE-RPC spoolss and IRemoteWinspool Calls Indicating Windows Print-Related Persistence

Alerts on specific Zeek DCE-RPC endpoint/operation combinations linked to Windows persistence techniques.

FreeReviewedSigma · Medium · v2
Product
zeek
Service
dce_rpc
Author
@neu5ron, SOC Prime (SigmaHQ), DRL 1.1
Published
2020-03-19
Updated
2026-07-31

ATT&CK techniques

Persistence → Priv Esc
  1. Recon

  2. Resource Dev

  3. Initial Access

  4. Execution

  5. Defense Evasion

  6. Cred Access

  7. Discovery

  8. Lateral Movement

  9. Collection

  10. C2

  11. Exfiltration

  12. Impact

What it detects

This rule matches Zeek DCE-RPC requests where specific endpoints and operations are used that align with Windows persistence techniques. Attackers can abuse these remote procedure calls to register or add print or monitor components and trigger persistence on the affected system. The detection relies on Zeek DCE-RPC telemetry that reports the RPC endpoint and operation names for remote calls.

Related detections7 linkedT1547.004 — drag to rearrange
Malicious Winlogon Shell or Userinit Persistence Modification (via registry_set)
Suspicious Command Prompt Spawned by Winlogon
Suspicious Winlogon Loading Keyboard Layout DLL kbdus1.dll
Malicious Winlogon Shell Persistence Modification (via registry_set)
Linux File Creation Indicators for TanStack Runner and Persistence Components
Windows Winlogon Notify Registry Key DLL Persistence (logon)
PowerShell ScriptBlock Winlogon Registry Modification via CurrentVersion\Winlogon
Zeek DCE-RPC spoolss and IRemoteWinspool Calls Indicating Windows Print-Related Persistence
Pivot detection · T1547.004 · 7 related

Changelog

v2
  1. v2
    Candidate ingested via manual entry.2026-07-31
  2. v1
    No changelog recorded for this version.2026-07-30

Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.