"Search the artifacts on the endpoint to determine if the employee used any of the Windows Printer Spooler vulnerabilities to elevate their privileges."
Follow/Connect:
Blog: https://micahsoday.github.io
LinkedIn: https://www.linkedin.com/in/micah-fun...
TryHackMe: https://tryhackme.com/p/M0dChild
Link to Room:
https://tryhackme.com/room/printnightmarec2bn7l
References:
https://www.gravwell.io/blog/whats-in-a-sysmon-event-windows-registry-eventids-12-13-14
https://0xdf.gitlab.io/2018/11/08/powershell-history-file.html
Follow/Connect:
Blog: https://micahsoday.github.io
LinkedIn: https://www.linkedin.com/in/micah-fun...
TryHackMe: https://tryhackme.com/p/M0dChild
Link to Room:
https://tryhackme.com/room/printnightmarec2bn7l
References:
https://www.gravwell.io/blog/whats-in-a-sysmon-event-windows-registry-eventids-12-13-14
https://0xdf.gitlab.io/2018/11/08/powershell-history-file.html
- Category
- Job

Be the first to comment