""ET POLICY [MS-PAR] Windows Printer Spooler Activity - RpcAsyncCorePrinterDriverInstalled""

SID: 2033263

Revision: 3

Class Type: misc-activity

Metadata: created_at 2021_07_06, signature_severity Informational, updated_at 2021_07_14

Reference:

Protocol: tcp

Source Network: any

Source Port: any

Destination Network: [$HOME_NET,$HTTP_SERVERS]

Destination Port: [1024:5000,49152:]

Flow: established,to_server

Contents:

  • Value: "|00|"

Offset: 3

  • Value: "|10 00 00 00|"

  • Value: "|41 00 8e ca 40 99 2f 51 58 4c 88 a9 61 09 8d 68 96 bd|"

Within: 18

PCRE:

Special Options:

source