Esc
Port Monitors - T1547.010
(ATT&CK® Technique)
Definition
Adversaries may use port monitors to run an adversary supplied DLL during system boot for persistence or privilege escalation. A port monitor can be set through the AddMonitor API call to set a DLL to be loaded at startup. This DLL can be located in C:\Windows\System32 and will be loaded and run by the print spooler service, spoolsv.exe, under SYSTEM level permissions on boot.
D3FEND Inferred Relationships
Browse the D3FEND knowledge graph by clicking on the nodes below.