Yet another DCOM object for lateral movement
ID: 80e2fcfc-a94a-5309-9504-0c661323bade
STIX ID: report--80e2fcfc-a94a-5309-9504-0c661323bade
Feed Name: Securelist by Kaspersky
The report introduces a new DCOM abuse technique that leverages the COpenControlPanel/IOpenControlPanel interface to load registered Control Panel DLLs through the COM Surrogate (dllhost.exe) for remote code execution and persistence. It reviews the reliability and detections of existing Impacket dcomexec objects across Windows versions, details practical enumeration methods (PowerShell, C++, OleViewDotNet), and provides detection guidance such as monitoring specific Control Panel registry paths, dllhost.exe hosting unusual COM objects, and Remote Registry usage.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
