Techniques › T1021 › T1021.003
T1021.003 Distributed Component Object Model
lateral movement — Windows · attack.mitre.org · JSON
1
MITRE detection strategy
1
analytics
13
Sigma rules tagged attack.t1021.003
0
KEV CVEs mapped here
<p>Adversaries may use Valid Accounts to interact with remote machines by taking advantage of Distributed Component Object Model (DCOM). The adversary may then perform actions as the logged-on user.</p><p>The Windows Component Object Model (COM) is a component of the native Windows application programming interface (API) that enables interaction between software objects, or executable code that implements one or more interfaces. Through COM, a client object can call methods of server objects, which are typically Dynamic Link Libraries (DLL) or executables (EXE). Distributed COM (DCOM) is transparent middleware that extends the functionality of COM beyond a local computer using remote procedure call (RPC) technology.</p><p>Permissions to interact with local and remote server COM objects are specified by access control lists (ACL) in the Registry. By default, only Administrators may remotely activate and launch COM objects through DCOM.</p><p>Through DCOM, adversaries operating in the context of an appropriately privileged user can remotely obtain arbitrary and even direct shellcode execution through Office applications as well as other Windows objects that contain insecure methods. DCOM can also execute macros in existing documents and may also invoke Dynamic Data Exchange (DDE) execution directly through a COM created instance of a Microsoft Office application, bypassing the need for a malicious document. DCOM can be used as a method of remotely interacting with Windows Management Instrumentation.</p>
KEV CVEs mapped to this technique · CTID Mappings Explorer
None. No KEV entry in the public mapping names this technique. Given that 74.7% of KEV has no mapping at all, this says more about the mapping than about the technique.
Detection strategy · ATT&CK Enterprise v19.2
- DET0285 Multi-Event Behavioral Detection for DCOM-Based Remote Code Execution v1.0
AN0791 WindowsA remote DCOM invocation by a privileged account using RPC (port 135), followed by abnormal process instantiation or module loading on the remote system indicative of code execution.Tunable:
TimeWindowUserContextProcessNameRemoteHostList
Sigma rules · SigmaHQ da9bb07d64, tag attack.t1021.003
Author: Karneades, Swisscom CSIRT
· 2019-08-05 (modified 2022-07-14) · logsource: product=windows category=process_creation · 05a2ab7e-ce11-4b63-86db-ab32e763e11d
Detects a Windows command line executable started from MMC
Author: Ecco, oscd.community, Jonhnathan Ribeiro, Tim Rauch
· 2019-09-03 (modified 2023-02-21) · logsource: product=windows category=process_creation · 10c14723-61c7-4c75-92ca-9af245723ad2
Detects wmiexec/dcomexec/atexec/smbexec from Impacket framework
Author: Roberto Rodriguez @Cyb3rWard0g, Open Threat Research (OTR), wagga
· 2020-10-12 (modified 2022-12-18) · logsource: product=windows category=file_event · 2f7979ae-f82b-45af-ac1d-2b10e93b0baa
Detects potential DLL hijack of "iertutil.dll" found in the DCOM InternetExplorer.Application Class over the network
Author: Aaron Stratton
· 2023-11-13 · logsource: product=windows category=process_creation · 551d9c1f-816c-445b-a7a6-7a3864720d60
Detects suspicious child processes of Excel which could be an indicator of lateral movement leveraging the "ActivateMicrosoftApp" Excel DCOM object.
Author: Sagie Dulce, Dekel Paz
· 2022-01-01 · logsource: product=rpc_firewall category=application · 68050b10-e477-4377-a99b-3721b422d6ef
Detects remote RPC calls that performs remote DCOM operations. These could be abused for lateral movement via DCOM or WMI.
Author: Swachchhanda Shrawan Poudel (Nextron Systems)
· 2025-10-18 · logsource: product=windows category=image_load · 6e8fe0a8-ba0b-4a93-8f9e-82657e7a5984
Detects BitLocker Access Agent Update Utility (baaupdate.exe) loading DLLs from suspicious locations that are publicly writable which could indicate an attempt to lateral movement via BitLocker DCOM & COM Hijacking.
This technique abuses COM Classes configured as INTERACTIVE USER to spawn processes in the context of the logged-on user's session. Specifically, it targets the BDEUILauncher Class (CLSID ab93b6f1-be76-4185-a488-a9001b105b94)
which can launch BaaUpdate.exe, which is vulnerable to COM Hijacking when started with input parameters. This allows attackers to execute code in the user's context without needing to steal credentials or use additional techniques to compromise the account.
Author: andrewdanis
· 2025-10-23 · logsource: product=windows category=process_creation · 78f10490-f2f4-4d19-a75b-4e0683bf3b8d
Detects suspicious Speech Runtime Binary Execution by monitoring its child processes.
Child processes spawned by SpeechRuntime.exe could indicate an attempt for lateral movement via COM & DCOM hijacking.
Author: andrewdanis, Swachchhanda Shrawan Poudel (Nextron Systems)
· 2025-10-18 · logsource: product=windows category=process_creation · 9f38c1db-e2ae-40bf-81d0-5b68f73fb512
Detects the execution of the BitLocker Access Agent Update Utility (baaupdate.exe) which is not a common parent process for other processes.
Suspicious child processes spawned by baaupdate.exe could indicate an attempt at lateral movement via BitLocker DCOM & COM Hijacking.
Author: Roberto Rodriguez (Cyb3rWard0g), OTR (Open Threat Research)
· 2020-06-24 (modified 2026-07-28) · logsource: product=windows category=image_load · ad1f4bb9-8dfb-4765-adb6-2a7cfb6c0f94
Detects signs of potential use of the WSMAN provider from uncommon processes locally and remote execution.
Author: Roberto Rodriguez @Cyb3rWard0g, Open Threat Research (OTR)
· 2020-10-12 (modified 2022-11-26) · logsource: product=windows service=security · c39f0c81-7348-4965-ab27-2fde35a1b641
Detects a threat actor creating a file named `iertutil.dll` in the `C:\Program Files\Internet Explorer\` directory over the network for a DCOM InternetExplorer DLL Hijack scenario.
Author: Roberto Rodriguez (Cyb3rWard0g), OTR (Open Threat Research)
· 2020-06-24 (modified 2025-10-22) · logsource: product=windows service=powershell-classic · df9a0e0e-fedb-4d6c-8668-d765dfc92aa7
Detects suspicious use of the WSMAN provider without PowerShell.exe as the host application.
Author: @2xxeformyshirt (Security Risk Advisors) - rule; Teymur Kheirkhabarov (idea)
· 2020-03-04 (modified 2021-11-27) · logsource: product=windows category=process_creation · f1f3bf22-deb2-418d-8cce-e1a45e46a5bd
Detects MMC20.Application Lateral Movement; specifically looks for the spawning of the parent MMC.exe with a command line of "-Embedding" as a child of svchost.exe
Author: Roberto Rodriguez @Cyb3rWard0g, Open Threat Research (OTR), wagga
· 2020-10-12 (modified 2022-12-18) · logsource: product=windows category=image_load · f354eba5-623b-450f-b073-0b5b2773b6aa
Detects potential DLL hijack of "iertutil.dll" found in the DCOM InternetExplorer.Application Class
Rules tagged at the parent level (attack.t1021) 11
These target the parent technique, not this sub-technique specifically. Listed for completeness, not counted as coverage.
Author: Security Onion Solutions
· 2024-03-08 · logsource: product=opencanary category=application · 22777c9e-873a-4b49-855f-6072ab861a52
Detects instances where an SMB service on an OpenCanary node has had a file open request.
Author: Security Onion Solutions
· 2024-03-08 · logsource: product=opencanary category=application · 6991bc2b-ae2e-447f-bc55-3a1ba04c14e5
Detects instances where an FTP service on an OpenCanary node has had a login attempt.
Author: omkar72
· 2020-10-30 (modified 2023-02-28) · logsource: product=windows category=process_creation · 730fc21b-eaff-474b-ad23-90fd265d4988
Detects user accept agreement execution in psexec commandline
Author: Chirag Damani
· 2026-03-29 · logsource: product=windows category=process_creation · 7638e5fe-600c-4289-a968-f49dd537ec7d
Detects execution of the hacktool NetExec.
NetExec (formerly CrackMapExec) is a widely used post-exploitation tool designed for Active Directory penetration testing and network enumeration
In enterprise environments, the use of NetExec is considered suspicious or potentially malicious because it enables attackers to enumerate hosts, exploit network services, and move laterally across systems.
Threat actors and red teams commonly use NetExec to identify vulnerable systems, harvest credentials, and execute commands remotely.
Author: Tim Rauch, Elastic (idea)
· 2022-09-27 · logsource: product=windows category=process_creation · 8a3038e8-9c9d-46f8-b184-66234a160f6f
Detects potential use of an SSH utility to establish RDP over a reverse SSH Tunnel. This can be used by attackers to enable routing of network packets that would otherwise not reach their intended destination.
Author: Tim Rauch, Elastic (idea)
· 2022-09-27 (modified 2022-12-30) · logsource: product=windows category=process_creation · 9bd04a79-dabe-4f1f-a5ff-92430265c96b
Detects a remote file copy attempt to a hidden network share. This may indicate lateral movement or data staging activity.
Author: Security Onion Solutions
· 2024-03-08 · logsource: product=opencanary category=application · 9db5446c-b44a-4291-8b89-fcab5609c3b3
Detects instances where a VNC service on an OpenCanary node has had a connection attempt.
Author: Security Onion Solutions
· 2024-03-08 · logsource: product=opencanary category=application · cd55f721-5623-4663-bd9b-5229cab5237d
Detects instances where an SSH service on an OpenCanary node has had a connection attempt.
Author: Security Onion Solutions
· 2024-03-08 · logsource: product=opencanary category=application · e9856028-fd4e-46e6-b3d1-10f7ceb95078
Detects instances where an SNMP service on an OpenCanary node has had an OID request.
Author: Josh Nickels
· 2024-05-10 · logsource: product=windows category=network_connection · fda34293-718e-4b36-b018-38caab0d1209
Detects an RDP connection originating from a domain controller.
Author: Security Onion Solutions
· 2024-03-08 · logsource: product=opencanary category=application · ff7139bc-fdb1-4437-92f2-6afefe8884cb
Detects instances where an SSH service on an OpenCanary node has had a login attempt.