A follow-up post from Huntress analysts documenting observed credential theft techniques using the print.exe LOLBin (Living Off the Land Binary) in real-world incidents. Attackers used print.exe alongside Volume Shadow Copies (VSC) to extract sensitive Windows credential files (NTDS.DIT, SAM, SYSTEM) without leaving the usual Windows Event Log artifacts. The post also notes that print.exe is used legitimately over 16,000 times per day across the Huntress customer base, making detection of malicious use challenging. The goal is to help security professionals recognize and build detection strategies for this technique.
1 Impression