PrintNightmare Spooler Exploitation - Suspicious Child Process or DLL Drop
Detects suspicious activity related to the Print Spooler service (spoolsv.exe), specifically focusing on the spawning of known command-line interpreters (cmd.exe, powershell.exe, rundll32.exe) by spoolsv.exe, as well as the creation or modification of DLL files within the system print spool drivers directory by processes other than spoolsv.exe. This activity is often associated with privilege escalation and persistence techniques involving print spooler service abuse.
Microsoft Sentinel (KQL)

