external_printing_connections

Explanation

This event is designed to detect external connections to internal print servers. The event triggers when an external source tries to connect to a print server residing within the protected network. This event is helpful in identifying potential threats that may compromise the confidentiality or integrity of the network.

What to Look For

When analyzing the results of this event, it is important to look for any attempts by external sources to connect to internal print servers. This could indicate an attempted intrusion or a compromised endpoint on the network. It is also important to examine the print server logs for any unusual activity, such as unexpected print jobs or unauthorized access. Remediation should include isolating compromised endpoints, blocking unauthorized access attempts, and implementing stronger security measures to prevent similar incidents in the future.

Related MITRE ATT&CK Categories