Detections
- Home
- - Detections
- -DT006
- ID: DT006
- Created: 25th May 2024
- Updated: 19th June 2024
- Platform: Windows
- Contributor: The ITM Team
Installed Printers via Registry
The Windows Registry stores information about installed printers and their configurations. The following registry keys can be useful to investigators:
- Printer settings -
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Print\Printers
- User-specific settings -
HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Devices
Sections
ID | Name | Description |
---|---|---|
PR013 | Testing Ability to Print | A subject attempts to print a document from a system to identify if this capability is permitted, restricted, or not possible. |
ME014 | Printing | A subject has the ability to print documents and other files. |
IF006 | Unauthorized Printing of Documents | A subject exfiltrates information by printing it to paper or other physical medium. |
IF006.001 | Printing of Documents with Personal Printer | A subject prints a document using a printer they own, physically exfiltrating the information. |
IF006.002 | Printing of Documents with Work Printer | A subject prints a document using a printer owned by the organization, with the intent to physically exfiltrate the information. |
ME014.001 | External Printing | A subject has the ability to print documents and other files with a printer outside of the organisation’s control. |
IF002.005 | Exfiltration via Physical Documents | A subject tansports physical documents outside of the control of the organization. |