DCOM Explained: How Attackers Turn a Windows Feature into a Lateral Movement Tool
ID: 494065ee-dffe-5347-bccb-0305d120a220
STIX ID: report--494065ee-dffe-5347-bccb-0305d120a220
Feed Name: Detect FYI
Threat Score
This report outlines detection and prevention techniques for lateral movement via DCOM: it provides example Security and Sysmon events showing remote logons, RPC over port 135, DCOM-host processes (e.g., mmc.exe) launched by svchost, and child shells executing a PowerShell downloader; it also describes a correlation rule and mitigations (block TCP 135, remove remote activation rights for non-admins, deploy LAPS).
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
