DCOM Again: Installing Trouble
ID: d98d5c3d-fe78-5ad1-9937-66adb834c73d
STIX ID: report--d98d5c3d-fe78-5ad1-9937-66adb834c73d
Feed Name: SpecterOps Blog
The report presents a DCOM lateral movement technique leveraging the Windows Installer Custom Action server to trigger execution of attacker-controlled DLLs by abusing ODBC driver installation and configuration (SQLInstallDriverEx and SQLConfigDriver), with execution occurring under msiexec in the target user context. It includes reverse engineering insights into MSI/COM interfaces, a released Beacon Object File to operationalize the method locally or remotely with valid credentials, and defensive guidance to monitor ODBC-related registry changes that indicate driver installation.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
