Port Monitors - T1547.010
(ATT&CK® Technique)
Adversaries may use port monitors to run an adversary supplied DLL during system boot for persistence or privilege escalation. A port monitor can be set through the AddMonitor
API call to set a DLL to be loaded at startup. This DLL can be located in C:\Windows\System32
and will be loaded and run by the print spooler service, spoolsv.exe
, under SYSTEM level permissions on boot.
D3FEND Inferred Relationships
Browse the D3FEND knowledge graph by clicking on the nodes below.