LoFP LoFP / domain controllers acting as printer servers too? :)

Techniques

Sample rules

DCERPC SMB Spoolss Named Pipe

Description

Detects the use of the spoolss named pipe over SMB. This can be used to trigger the authentication via NTLM of any machine that has the spoolservice enabled.

Detection logic

condition: selection
selection:
  EventID: 5145
  RelativeTargetName: spoolss
  ShareName: \\\\\*\\IPC$