AN0791
Analytic 0791
Windows
A remote DCOM invocation by a privileged account using RPC (port 135), followed by abnormal process instantiation or module loading on the remote system indicative of code execution.
WinEventLog:Security
EventCode=4624, 4648
WinEventLog:Sysmon
EventCode=3, 22
WinEventLog:Sysmon
EventCode=1
WinEventLog:Sysmon
EventCode=7
[TimeWindow]
Correlate RPC activity with remote process creation within a configurable time window (e.g., 300s)
[UserContext]
Identify rare or first-time DCOM invocations by specific accounts
[ProcessName]
List of suspicious executables commonly abused via DCOM (e.g., excel.exe, wmiprvse.exe)
[RemoteHostList]
Known set of systems that should or should not be invoking DCOM activity