Threaticon
Toggle sidebar

You're viewing a limited, public preview. Log in for full access.

Log in User Guide
Log in Get started
Detection Strategies DET0224 — Detect Abuse of Component Object Model (T1559.001)
DET0224

Detect Abuse of Component Object Model (T1559.001)

1 analytic(s) · 1 technique(s) detected

Analytics

1
AN0628 Analytic 0628
Windows

Detects anomalous use of COM objects for execution, such as Office applications spawning scripting engines, enumeration of COM interfaces via registry queries, or processes loading atypical DLLs through COM activation. Correlates process creation, module loads, and registry queries to flag suspicious COM-based code execution or persistence.

WinEventLog:Sysmon EventCode=1 WinEventLog:Sysmon EventCode=7 WinEventLog:Security EventCode=4663, 4670, 4656
[COMObjectAllowList] Legitimate COM CLSIDs and ProgIDs used by enterprise applications, to reduce false positives.
[ParentProcessExclusions] Expected parent-child process relationships (e.g., explorer.exe spawning dllhost.exe).
[TimeWindow] Threshold for correlating COM object execution with subsequent process creation or DLL load.

Detected Techniques

1

Details

MITRE ID
DET0224
STIX ID
x-mitre-detection-strategy--96c3e267-9dde-45cb-b700-e27c1a672cf8
Analytics
1
Techniques Detected
1
By Tactic
Execution
1
Leaving Threaticon

This link opens an external site that isn't part of the platform.