Analytics BIOC Low

Remote DCOM command execution

A remotely triggered DCOM initiated a command execution by a host that rarely executes processes using DCOM to other remote hosts.

Module:
Platform Analytics
Data source:
XDR Agent
ATT&CK tactics: Lateral Movement (TA0008)
ATT&CK techniques: Remote Services: Distributed Component Object Model (T1021.003)
Detector tags: Impacket Analytics
Attacker's goals:

Perform lateral movement to new hosts to expand the foothold within a network.

Investigative actions:

Investigate the processes being spawned on the host for malicious activities. Correlate the DCOM call from the source host and understand which software initiated it.

Test period:
N/A (single event)
Deduplication:
1 Day
4 variations:
  • Remote suspicious DCOM-MMC20.Application command execution High (parent: Low)
  • Remote suspicious DCOM-Excel.Application command execution High (parent: Low)
  • Remote suspicious DCOM-Outlook.Application command execution High (parent: Low)
  • Remote suspicious DCOM command execution Medium (parent: Low)