PrintService Event ID 808: Spooler plug-in load failed
- Event ID
- 808
- Channel
- Microsoft-Windows-PrintService/Admin
- Provider
- Microsoft-Windows-PrintService
- Log file
- Microsoft-Windows-PrintService%4Operational.evtx
- Category
- Software
- Default logging
- Logged by default
What event 808 means
Event 808 is written to Microsoft-Windows-PrintService/Admin when the spooler (spoolsv.exe) cannot load a plug-in module such as a printer driver, rendering or configuration DLL. The message gives the DLL path and an error code.
Day to day, it comes from broken or mismatched printer drivers: a missing file (0x7e), a 32/64-bit mismatch (0xc1) and similar. It became a key detection during PrintNightmare (CVE-2021-1675 / CVE-2021-34527): exploits make the spooler load an attacker-supplied DLL as a printer driver, and many payload DLLs are not valid driver plug-ins, so the spooler reports the load as failed — typically with 0x45A — after the DLL's code has already run as SYSTEM.
A DLL under C:\Windows\System32\spool\drivers\x64\3\ with a name that does not belong to any installed driver, or a path on a remote share, is the pattern to look for.
When it is logged
Microsoft-Windows-PrintService/Admin log, enabled by default.
Successful malicious driver loads may produce no 808 at all; also review the PrintService Operational log (disabled by default) and file creation in the spool drivers folder.
Key fields
| Field | What it tells you | ||||||||
|---|---|---|---|---|---|---|---|---|---|
| ErrorCode | Win32 error returned when loading the module.
|
Common benign sources
- Old or incompatible printer drivers that fail to load after upgrades.
- Leftover driver files from removed printers.
What attackers do that produces it
- PrintNightmare exploitation: a remote or local attacker installs a malicious DLL as a printer driver; the spooler executes it as SYSTEM and logs 808 with
0x45A. - Local privilege escalation or lateral movement through the spooler on unpatched hosts.
Investigation tips
- Check the DLL path in the message; unknown DLL names in the spool drivers folder, user folders or UNC paths are suspicious.
- Hash and retrieve the DLL; look for its creation (Sysmon 11) and child processes of
spoolsv.exe(4688, Sysmon 1). - Look for the preceding network logon (4624 type 3) and SMB access to the spooler pipe (5145) to find the source.
- Confirm the patch level and whether the Print Spooler service is needed on the host (disable it on domain controllers).
MITRE ATT&CK techniques
MITRE ATT&CK v19.2. Technique and tactic names are MITRE's.
Sigma rules for this event
No bundled SigmaHQ rule targets this event ID specifically. Rules on related events may still cover the activity.
Run these rules on your logs
Drop a .evtx file into the viewer: all 2,395 bundled SigmaHQ rules run locally in your browser. Nothing is uploaded.