Analytics BIOC
Informational
✕
Rare DCOM RPC activity
The endpoint performed abnormal DCOM RPC activity to a remote host.
- Module:
- Platform Analytics
- Data source:
- Palo Alto Networks Firewall EAL Logs, XDR Agent with eXtended Threat Hunting (XTH)
ATT&CK tactics: Lateral Movement (TA0008)
ATT&CK techniques: Remote Services: Distributed Component Object Model (T1021.003)
Detector tags: NDR Lateral Movement Analytics
Attacker's goals:
Attackers may attempt to gain persistence or move laterally over the network by executing code on remote hosts using the DCOM RPC interface. The DCOM RPC interface is used to remotely invoke registered COM applications on remote hosts.
Investigative actions:
Review the action of the initiated COM application on the remote host. Correlate the RPC call from the source host and understand which software initiated it.* Verify that this isn't IT activity.
- Test period:
- N/A (single event)
- Deduplication:
- 1 Day
1 variation:
- Rare DCOM RPC activity Low (parent: Informational)