- Tactics
- Persistence, Privilege Escalation
- Platforms
- Windows
- Reference
- attack.mitre.org/techniques/T1547.010
Description
Adversaries may use port monitors to run an adversary supplied DLL during system boot for persistence or privilege escalation. A port monitor can be set through the AddMonitor API call to set a DLL to be loaded at startup.(Citation: AddMonitor) This DLL can be located in C:\Windows\System32 and will be loaded and run by the print spooler service, spoolsv.exe, under SYSTEM level permissions on boot.(Citation: Bloxham)
Alternatively, an arbitrary DLL can be loaded if permissions allow writing a fully-qualified pathname for that DLL to the Driver value of an existing or new arbitrarily named subkey of HKLM\SYSTEM\CurrentControlSet\Control\Print\Monitors. The Registry key contains entries for the following:
- Local Port
- Standard TCP/IP Port
- USB Monitor
- WSD Port
How GTK Cyber trains on this
GTK Cyber's Threat Hunting with Data Science course teaches you to build machine-learning detections for techniques like this across the MITRE ATT&CK framework, including the Persistence, Privilege Escalation tactic this technique falls under. Practitioner-led, focused on real detections, not memorizing technique IDs.
Related techniques
- T1037 - Boot or Logon Initialization Scripts
- T1053 - Scheduled Task/Job
- T1055 - Process Injection
- T1068 - Exploitation for Privilege Escalation
- T1078 - Valid Accounts
- T1098 - Account Manipulation
- T1112 - Modify Registry
- T1133 - External Remote Services
- T1134 - Access Token Manipulation
- T1136 - Create Account
- T1137 - Office Application Startup
- T1176 - Software Extensions