{"id":"T1021.003","name":"Distributed Component Object Model","url":"https://attack.mitre.org/techniques/T1021/003","tactics":["lateral-movement"],"platforms":["Windows"],"live":true,"revoked":false,"deprecated":false,"revoked_by":null,"detection_strategies":[{"id":"DET0285","stix_id":"x-mitre-detection-strategy--dbaaa57a-ef28-44c0-bc56-25bc20dc8f28","name":"Multi-Event Behavioral Detection for DCOM-Based Remote Code Execution","url":"https://attack.mitre.org/detectionstrategies/DET0285","analytics":[{"id":"AN0791","stix_id":"x-mitre-analytic--0f94823c-ac95-48d8-9716-58f59d39974c","name":"Analytic 0791","description":"A remote DCOM invocation by a privileged account using RPC (port 135), followed by abnormal process instantiation or module loading on the remote system indicative of code execution.","url":"https://attack.mitre.org/detectionstrategies/DET0285#AN0791","platforms":["Windows"],"log_source_references":[{"name":"WinEventLog:Security","channel":"EventCode=4624, 4648","data_component":"DC0067","data_component_name":"Logon Session Creation","log_source_slug":"wineventlog-security"},{"name":"WinEventLog:Sysmon","channel":"EventCode=3, 22","data_component":"DC0082","data_component_name":"Network Connection Creation","log_source_slug":"wineventlog-sysmon"},{"name":"WinEventLog:Sysmon","channel":"EventCode=1","data_component":"DC0032","data_component_name":"Process Creation","log_source_slug":"wineventlog-sysmon"},{"name":"WinEventLog:Sysmon","channel":"EventCode=7","data_component":"DC0016","data_component_name":"Module Load","log_source_slug":"wineventlog-sysmon"}],"mutable_elements":[{"field":"TimeWindow","description":"Correlate RPC activity with remote process creation within a configurable time window (e.g., 300s)"},{"field":"UserContext","description":"Identify rare or first-time DCOM invocations by specific accounts"},{"field":"ProcessName","description":"List of suspicious executables commonly abused via DCOM (e.g., excel.exe, wmiprvse.exe)"},{"field":"RemoteHostList","description":"Known set of systems that should or should not be invoking DCOM activity"}],"live":true,"detection_strategies":["DET0285"],"techniques":["T1021.003"]}],"live":true,"version":"1.0","techniques":["T1021.003"]}],"sigma_rules":[{"id":"05a2ab7e-ce11-4b63-86db-ab32e763e11d","title":"MMC Spawning Windows Shell","author":"Karneades, Swisscom CSIRT","status":"test","level":"high","date":"2019-08-05","modified":"2022-07-14","description":"Detects a Windows command line executable started from MMC","references":["https://enigma0x3.net/2017/01/05/lateral-movement-using-the-mmc20-application-com-object/"],"logsource":{"product":"windows","category":"process_creation"},"tags":["attack.lateral-movement","attack.t1021.003"],"path":"rules/windows/process_creation/proc_creation_win_mmc_susp_child_process.yml","techniques":["T1021.003"],"cves":[]},{"id":"10c14723-61c7-4c75-92ca-9af245723ad2","title":"HackTool - Potential Impacket Lateral Movement Activity","author":"Ecco, oscd.community, Jonhnathan Ribeiro, Tim Rauch","status":"stable","level":"high","date":"2019-09-03","modified":"2023-02-21","description":"Detects wmiexec/dcomexec/atexec/smbexec from Impacket framework","references":["https://github.com/SecureAuthCorp/impacket/blob/8b1a99f7c715702eafe3f24851817bb64721b156/examples/wmiexec.py","https://github.com/SecureAuthCorp/impacket/blob/8b1a99f7c715702eafe3f24851817bb64721b156/examples/atexec.py","https://github.com/SecureAuthCorp/impacket/blob/8b1a99f7c715702eafe3f24851817bb64721b156/examples/smbexec.py","https://github.com/SecureAuthCorp/impacket/blob/8b1a99f7c715702eafe3f24851817bb64721b156/examples/dcomexec.py","https://www.elastic.co/guide/en/security/current/suspicious-cmd-execution-via-wmi.html"],"logsource":{"product":"windows","category":"process_creation"},"tags":["attack.execution","attack.t1047","attack.lateral-movement","attack.t1021.003"],"path":"rules/windows/process_creation/proc_creation_win_hktl_impacket_lateral_movement.yml","techniques":["T1047","T1021.003"],"cves":[]},{"id":"2f7979ae-f82b-45af-ac1d-2b10e93b0baa","title":"Potential DCOM InternetExplorer.Application DLL Hijack","author":"Roberto Rodriguez @Cyb3rWard0g, Open Threat Research (OTR), wagga","status":"test","level":"critical","date":"2020-10-12","modified":"2022-12-18","description":"Detects potential DLL hijack of \"iertutil.dll\" found in the DCOM InternetExplorer.Application Class over the network","references":["https://threathunterplaybook.com/hunts/windows/201009-RemoteDCOMIErtUtilDLLHijack/notebook.html"],"logsource":{"product":"windows","category":"file_event"},"tags":["attack.lateral-movement","attack.t1021.002","attack.t1021.003"],"path":"rules/windows/file/file_event/file_event_win_dcom_iertutil_dll_hijack.yml","techniques":["T1021.002","T1021.003"],"cves":[]},{"id":"551d9c1f-816c-445b-a7a6-7a3864720d60","title":"Potential Excel.EXE DCOM Lateral Movement Via ActivateMicrosoftApp","author":"Aaron Stratton","status":"test","level":"high","date":"2023-11-13","modified":null,"description":"Detects suspicious child processes of Excel which could be an indicator of lateral movement leveraging the \"ActivateMicrosoftApp\" Excel DCOM object.\n","references":["https://posts.specterops.io/lateral-movement-abuse-the-power-of-dcom-excel-application-3c016d0d9922","https://github.com/grayhatkiller/SharpExShell","https://learn.microsoft.com/en-us/office/vba/api/excel.xlmsapplication"],"logsource":{"product":"windows","category":"process_creation"},"tags":["attack.t1021.003","attack.lateral-movement"],"path":"rules/windows/process_creation/proc_creation_win_office_excel_dcom_lateral_movement.yml","techniques":["T1021.003"],"cves":[]},{"id":"68050b10-e477-4377-a99b-3721b422d6ef","title":"Remote DCOM/WMI Lateral Movement","author":"Sagie Dulce, Dekel Paz","status":"test","level":"high","date":"2022-01-01","modified":null,"description":"Detects remote RPC calls that performs remote DCOM operations. These could be abused for lateral movement via DCOM or WMI.","references":["https://learn.microsoft.com/en-us/openspecs/windows_protocols/ms-srvs/accf23b0-0f57-441c-9185-43041f1b0ee9","https://github.com/zeronetworks/rpcfirewall","https://zeronetworks.com/blog/stopping-lateral-movement-via-the-rpc-firewall/"],"logsource":{"product":"rpc_firewall","category":"application"},"tags":["attack.lateral-movement","attack.execution","attack.t1021.003","attack.t1047"],"path":"rules/application/rpc_firewall/rpc_firewall_remote_dcom_or_wmi.yml","techniques":["T1021.003","T1047"],"cves":[]},{"id":"6e8fe0a8-ba0b-4a93-8f9e-82657e7a5984","title":"BaaUpdate.exe Suspicious DLL Load","author":"Swachchhanda Shrawan Poudel (Nextron Systems)","status":"experimental","level":"high","date":"2025-10-18","modified":null,"description":"Detects BitLocker Access Agent Update Utility (baaupdate.exe) loading DLLs from suspicious locations that are publicly writable which could indicate an attempt to lateral movement via BitLocker DCOM & COM Hijacking.\nThis technique abuses COM Classes configured as INTERACTIVE USER to spawn processes in the context of the logged-on user's session. Specifically, it targets the BDEUILauncher Class (CLSID ab93b6f1-be76-4185-a488-a9001b105b94)\nwhich can launch BaaUpdate.exe, which is vulnerable to COM Hijacking when started with input parameters. This allows attackers to execute code in the user's context without needing to steal credentials or use additional techniques to compromise the account.\n","references":["https://github.com/rtecCyberSec/BitlockMove"],"logsource":{"product":"windows","category":"image_load"},"tags":["attack.stealth","attack.t1218","attack.lateral-movement","attack.t1021.003"],"path":"rules/windows/image_load/image_load_susp_baaupdate_dll_load.yml","techniques":["T1218","T1021.003"],"cves":[]},{"id":"78f10490-f2f4-4d19-a75b-4e0683bf3b8d","title":"Suspicious Speech Runtime Binary Child Process","author":"andrewdanis","status":"experimental","level":"high","date":"2025-10-23","modified":null,"description":"Detects suspicious Speech Runtime Binary Execution by monitoring its child processes.\nChild processes spawned by SpeechRuntime.exe could indicate an attempt for lateral movement via COM & DCOM hijacking.\n","references":["https://github.com/rtecCyberSec/SpeechRuntimeMove"],"logsource":{"product":"windows","category":"process_creation"},"tags":["attack.lateral-movement","attack.stealth","attack.t1021.003","attack.t1218"],"path":"rules/windows/process_creation/proc_creation_win_speechruntime_child_process.yml","techniques":["T1021.003","T1218"],"cves":[]},{"id":"9f38c1db-e2ae-40bf-81d0-5b68f73fb512","title":"Suspicious BitLocker Access Agent Update Utility Execution","author":"andrewdanis, Swachchhanda Shrawan Poudel (Nextron Systems)","status":"experimental","level":"high","date":"2025-10-18","modified":null,"description":"Detects the execution of the BitLocker Access Agent Update Utility (baaupdate.exe) which is not a common parent process for other processes.\nSuspicious child processes spawned by baaupdate.exe could indicate an attempt at lateral movement via BitLocker DCOM & COM Hijacking.\n","references":["https://github.com/rtecCyberSec/BitlockMove"],"logsource":{"product":"windows","category":"process_creation"},"tags":["attack.stealth","attack.t1218","attack.lateral-movement","attack.t1021.003"],"path":"rules/windows/process_creation/proc_creation_win_baaupdate_susp_child_process.yml","techniques":["T1218","T1021.003"],"cves":[]},{"id":"ad1f4bb9-8dfb-4765-adb6-2a7cfb6c0f94","title":"Suspicious WSMAN Provider Image Loads","author":"Roberto Rodriguez (Cyb3rWard0g), OTR (Open Threat Research)","status":"test","level":"medium","date":"2020-06-24","modified":"2026-07-28","description":"Detects signs of potential use of the WSMAN provider from uncommon processes locally and remote execution.","references":["https://twitter.com/chadtilbury/status/1275851297770610688","https://bohops.com/2020/05/12/ws-management-com-another-approach-for-winrm-lateral-movement/","https://learn.microsoft.com/en-us/windows/win32/winrm/windows-remote-management-architecture","https://github.com/bohops/WSMan-WinRM"],"logsource":{"product":"windows","category":"image_load"},"tags":["attack.execution","attack.t1059.001","attack.lateral-movement","attack.t1021.003"],"path":"rules/windows/image_load/image_load_wsman_provider_image_load.yml","techniques":["T1059.001","T1021.003"],"cves":[]},{"id":"c39f0c81-7348-4965-ab27-2fde35a1b641","title":"DCOM InternetExplorer.Application Iertutil DLL Hijack - Security","author":"Roberto Rodriguez @Cyb3rWard0g, Open Threat Research (OTR)","status":"test","level":"high","date":"2020-10-12","modified":"2022-11-26","description":"Detects a threat actor creating a file named `iertutil.dll` in the `C:\\Program Files\\Internet Explorer\\` directory over the network for a DCOM InternetExplorer DLL Hijack scenario.","references":["https://threathunterplaybook.com/hunts/windows/201009-RemoteDCOMIErtUtilDLLHijack/notebook.html"],"logsource":{"product":"windows","service":"security"},"tags":["attack.lateral-movement","attack.t1021.002","attack.t1021.003"],"path":"rules/windows/builtin/security/win_security_dcom_iertutil_dll_hijack.yml","techniques":["T1021.002","T1021.003"],"cves":[]},{"id":"df9a0e0e-fedb-4d6c-8668-d765dfc92aa7","title":"Suspicious Non PowerShell WSMAN COM Provider","author":"Roberto Rodriguez (Cyb3rWard0g), OTR (Open Threat Research)","status":"test","level":"medium","date":"2020-06-24","modified":"2025-10-22","description":"Detects suspicious use of the WSMAN provider without PowerShell.exe as the host application.","references":["https://twitter.com/chadtilbury/status/1275851297770610688","https://bohops.com/2020/05/12/ws-management-com-another-approach-for-winrm-lateral-movement/","https://github.com/bohops/WSMan-WinRM"],"logsource":{"product":"windows","service":"powershell-classic"},"tags":["attack.execution","attack.t1059.001","attack.lateral-movement","attack.t1021.003"],"path":"rules/windows/powershell/powershell_classic/posh_pc_wsman_com_provider_no_powershell.yml","techniques":["T1059.001","T1021.003"],"cves":[]},{"id":"f1f3bf22-deb2-418d-8cce-e1a45e46a5bd","title":"MMC20 Lateral Movement","author":"@2xxeformyshirt (Security Risk Advisors) - rule; Teymur Kheirkhabarov (idea)","status":"test","level":"high","date":"2020-03-04","modified":"2021-11-27","description":"Detects MMC20.Application Lateral Movement; specifically looks for the spawning of the parent MMC.exe with a command line of \"-Embedding\" as a child of svchost.exe","references":["https://enigma0x3.net/2017/01/05/lateral-movement-using-the-mmc20-application-com-object/","https://drive.google.com/file/d/1lKya3_mLnR3UQuCoiYruO3qgu052_iS_/view?usp=sharing"],"logsource":{"product":"windows","category":"process_creation"},"tags":["attack.execution","attack.lateral-movement","attack.t1021.003"],"path":"rules/windows/process_creation/proc_creation_win_mmc_mmc20_lateral_movement.yml","techniques":["T1021.003"],"cves":[]},{"id":"f354eba5-623b-450f-b073-0b5b2773b6aa","title":"Potential DCOM InternetExplorer.Application DLL Hijack - Image Load","author":"Roberto Rodriguez @Cyb3rWard0g, Open Threat Research (OTR), wagga","status":"test","level":"critical","date":"2020-10-12","modified":"2022-12-18","description":"Detects potential DLL hijack of \"iertutil.dll\" found in the DCOM InternetExplorer.Application Class","references":["https://threathunterplaybook.com/hunts/windows/201009-RemoteDCOMIErtUtilDLLHijack/notebook.html"],"logsource":{"product":"windows","category":"image_load"},"tags":["attack.lateral-movement","attack.t1021.002","attack.t1021.003"],"path":"rules/windows/image_load/image_load_iexplore_dcom_iertutil_dll_hijack.yml","techniques":["T1021.002","T1021.003"],"cves":[]}],"kev_cves":[],"_built":"2026-08-24 19:45 UTC","_attack_version":"19.2","_sigma_commit":"da9bb07d642a2826e89702445d32c795209ec108"}