Suspicious Print System Remote Protocol usage by a process
Synopsis
Activation Period
14 Days
Training Period
30 Days
Test Period
N/A (single event)
Deduplication Period
1 Day
Required Data
XDR Agent with eXtended Threat Hunting (XTH)
Detection Modules
Identity Analytics
ATT&CK Tactic
Credential Access (TA0006)
ATT&CK Technique
Forced Authentication (T1187)
Severity
Low
Description
A host which is trusted for unconstrained delegation initiated an SMB connection to a DC using the Print System Remote Protocol. An attacker can abuse such sessions for relay attacks.
Attacker's Goals
Elevate privileges from standard domain user to domain admin.
Investigative actions
Check if the domain controller is patched or vulnerable to the attack.
Check if the suspected account is compromised.
Check if the source machine is trusted for unconstrained delegation and verify that the machine's configuration should stay that way.
Follow actions by the account and if it performed a DCSync.
Was this helpful?
