Description
This module establishes persistence by registering a malicious Print Processor DLL under HKLM\SYSTEM\CurrentControlSet\Control\Print\Environments\<arch>\Print Processors. The Print Spooler service loads configured processor DLLs at startup, causing payload execution when the spooler service starts (for example, on boot).
This module implements the manual registry method (not the AddMonitor API method). It writes the payload DLL to the print processor directory and requires SYSTEM or admin privileges to write to that directory and modify HKLM. The spooler service is briefly stopped and restarted to activate the registered processor.
Module options
To display the available options, load the module within the Metasploit console and run the commands 'show options' or 'show advanced':
msf > use exploit/windows/persistence/print/processormsf undefined(processor) > show actions ...actions...msf undefined(processor) > set ACTION < action-name >msf undefined(processor) > show options ...show and set options...msf undefined(processor) > runPrioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub