logo

DCOM Explained: How Attackers Turn a Windows Feature into a Lateral Movement Tool

ID: 494065ee-dffe-5347-bccb-0305d120a220

STIX ID: report--494065ee-dffe-5347-bccb-0305d120a220

Feed Name: Detect FYI

Threat Score
60/100

Date Published: 2026-06-18

Date Updated: 2026-06-19

Author: Zshan Hyder

...
...

This report outlines detection and prevention techniques for lateral movement via DCOM: it provides example Security and Sysmon events showing remote logons, RPC over port 135, DCOM-host processes (e.g., mmc.exe) launched by svchost, and child shells executing a PowerShell downloader; it also describes a correlation rule and mitigations (block TCP 135, remove remote activation rights for non-admins, deploy LAPS).

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.