ITM is an open framework - Submit your contributions now.

Insider Threat Matrix™

  • ID: DT006
  • Created: 25th May 2024
  • Updated: 19th June 2024
  • Platform: Windows
  • Contributor: The ITM Team

Installed Printers via Registry

The Windows Registry stores information about installed printers and their configurations. The following registry keys can be useful to investigators:

  • Printer settings -  HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Print\Printers
  • User-specific settings -  HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Devices

Sections

ID Name Description
PR013Testing Ability to Print

A subject attempts to print a document from a system to identify if this capability is permitted, restricted, or not possible.

ME014Printing

A subject has the ability to print documents and other files.

IF006Unauthorized Printing of Documents

A subject exfiltrates information by printing it to paper or other physical medium.

IF006.001Printing of Documents with Personal Printer

A subject prints a document using a printer they own, physically exfiltrating the information.

IF006.002Printing of Documents with Work Printer

A subject prints a document using a printer owned by the organization, with the intent to physically exfiltrate the information.

ME014.001External Printing

A subject has the ability to print documents and other files with a printer outside of the organisation’s control.

IF002.005Exfiltration via Physical Documents

A subject tansports physical documents outside of the control of the organization.