LoFP LoFP / domain controllers that are sometimes, commonly although should not be, acting as printer servers too

Techniques

Sample rules

SMB Spoolss Name Piped Usage

Description

Detects the use of the spoolss named pipe over SMB. This can be used to trigger the authentication via NTLM of any machine that has the spoolservice enabled.

Detection logic

condition: selection
selection:
  name: spoolss
  path|endswith: IPC$