Suspicious port monitor loaded
Identifies the loading of an unsigned DLL by the print spool service. Adversaries may use port monitors to run an adversary supplied DLL during system boot for persistence or privilege escalation.
- Platform: Windows
- Severity: High
- MITRE Tactic: Persistence
- MITRE Techniques: T1547, T1547.010