Suspicious port monitor loaded
Identifies the loading of an unsigned DLL by the print spool service. Adversaries may use port monitors to run an adversary supplied DLL during system boot for persistence or privilege escalation.
- Plataforma: Windows
- Severidad: High
- Táctica MITRE: Persistencia
- Técnicas MITRE: T1547, T1547.010