Threaticon
Toggle sidebar

You're viewing a limited, public preview. Log in for full access.

Log in User Guide
Log in Get started
Detection Strategies DET0285 — Multi-Event Behavioral Detection for DCOM-Based Remote Code Execution
DET0285

Multi-Event Behavioral Detection for DCOM-Based Remote Code Execution

1 analytic(s) · 1 technique(s) detected

Analytics

1
AN0791 Analytic 0791
Windows

A remote DCOM invocation by a privileged account using RPC (port 135), followed by abnormal process instantiation or module loading on the remote system indicative of code execution.

WinEventLog:Security EventCode=4624, 4648 WinEventLog:Sysmon EventCode=3, 22 WinEventLog:Sysmon EventCode=1 WinEventLog:Sysmon EventCode=7
[TimeWindow] Correlate RPC activity with remote process creation within a configurable time window (e.g., 300s)
[UserContext] Identify rare or first-time DCOM invocations by specific accounts
[ProcessName] List of suspicious executables commonly abused via DCOM (e.g., excel.exe, wmiprvse.exe)
[RemoteHostList] Known set of systems that should or should not be invoking DCOM activity

Detected Techniques

1

Details

MITRE ID
DET0285
STIX ID
x-mitre-detection-strategy--dbaaa57a-ef28-44c0-bc56-25bc20dc8f28
Analytics
1
Techniques Detected
1
By Tactic
Lateral Movement
1
Leaving Threaticon

This link opens an external site that isn't part of the platform.