{"id":20699,"date":"2021-07-17T00:54:00","date_gmt":"2021-07-16T22:54:00","guid":{"rendered":"http:\/\/159.69.82.204\/win\/?p=20699"},"modified":"2022-11-04T11:45:53","modified_gmt":"2022-11-04T10:45:53","slug":"microsoft-defender-for-identity-kann-printnightmare-angriffe-erkennen","status":"publish","type":"post","link":"https:\/\/borncity.com\/win\/2021\/07\/17\/microsoft-defender-for-identity-kann-printnightmare-angriffe-erkennen\/","title":{"rendered":"Microsoft Defender for Identity can detect PrintNightmare attacks"},"content":{"rendered":"<p><img decoding=\"async\" title=\"Sicherheit (Pexels, allgemeine Nutzung)\" style=\"float: left; margin: 0px 10px 0px 0px; display: inline\" alt=\"Sicherheit (Pexels, allgemeine Nutzung)\" src=\"https:\/\/www.borncity.com\/blog\/wp-content\/uploads\/2021\/04\/Sicherheit_klein.jpg\" width=\"200\" align=\"left\">[<a href=\"https:\/\/www.borncity.com\/blog\/?p=255760\" target=\"_blank\" rel=\"noopener\">German<\/a>]Microsoft Defender for Identity (formerly Azure Advanced Threat Protection or Azure ATP) has been given the ability by Microsoft to detect and defend against attacks via the PrintNightmare vulnerability. This primarily affects exploitation of vulnerabilities in the Windows Print Spooler service (including the actively exploited CVE-2021-34527).<\/p>\n<p><!--more--><\/p>\n<p>Microsoft program manager Daniel Naim just pointed out this issue on <a href=\"https:\/\/twitter.com\/danielmy1Daniel\/status\/1415695946164449288\" target=\"_blank\" rel=\"noopener\">Twitter<\/a>,&nbsp; which is described in <a href=\"https:\/\/docs.microsoft.com\/en-us\/defender-for-identity\/lateral-movement-alerts#suspected-exploitation-attempt-on-windows-print-spooler-service-external-id-2415\" target=\"_blank\" rel=\"noopener\">this article<\/a>. <\/p>\n<p><a href=\"https:\/\/twitter.com\/danielmy1Daniel\/status\/1415695946164449288\" target=\"_blank\" rel=\"noopener\"><img decoding=\"async\" title=\"Microsoft Defender for Identity\" alt=\"Microsoft Defender for Identity\" src=\"https:\/\/i.imgur.com\/lrOZeDD.png\"><\/a><\/p>\n<p>Colleagues at Bleeping Computer have published an article on the topic <a href=\"https:\/\/web.archive.org\/web\/20221008033739\/https:\/\/www.bleepingcomputer.com\/news\/security\/microsoft-defender-for-identity-now-detects-printnightmare-attacks\/\" target=\"_blank\" rel=\"noopener\">here<\/a>. <\/p>\n","protected":false},"excerpt":{"rendered":"<p>[German]Microsoft Defender for Identity (formerly Azure Advanced Threat Protection or Azure ATP) has been given the ability by Microsoft to detect and defend against attacks via the PrintNightmare vulnerability. This primarily affects exploitation of vulnerabilities in the Windows Print Spooler &hellip; <a href=\"https:\/\/borncity.com\/win\/2021\/07\/17\/microsoft-defender-for-identity-kann-printnightmare-angriffe-erkennen\/\">Continue reading <span class=\"meta-nav\">&rarr;<\/span><\/a><\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"open","ping_status":"","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[580,2],"tags":[646,69,194],"class_list":["post-20699","post","type-post","status-publish","format-standard","hentry","category-security","category-windows","tag-antivirus","tag-security","tag-windows"],"_links":{"self":[{"href":"https:\/\/borncity.com\/win\/wp-json\/wp\/v2\/posts\/20699","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/borncity.com\/win\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/borncity.com\/win\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/borncity.com\/win\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/borncity.com\/win\/wp-json\/wp\/v2\/comments?post=20699"}],"version-history":[{"count":0,"href":"https:\/\/borncity.com\/win\/wp-json\/wp\/v2\/posts\/20699\/revisions"}],"wp:attachment":[{"href":"https:\/\/borncity.com\/win\/wp-json\/wp\/v2\/media?parent=20699"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/borncity.com\/win\/wp-json\/wp\/v2\/categories?post=20699"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/borncity.com\/win\/wp-json\/wp\/v2\/tags?post=20699"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}