Loading interactive filters…
1200KM / detection
T1021.003 Distributed Component Object Model — Detection Rules
Detection workspace for T1021.003 Distributed Component Object Model: 13 Sigma sources, 0 Atlas concepts and 0 anomaly models. No live detection validation.
Source-backed rule directory
- Remote DCOM/WMI Lateral Movement · test · high · {"product":"rpc_firewall","category":"application","definition":"Requirements: install and apply the RPC Firewall to all processes with \"audit:true action:block uuid:367abb81-9844-35f1-ad32-98f038001003"}
- DCOM InternetExplorer.Application Iertutil DLL Hijack - Security · test · high · {"product":"windows","service":"security"}
- Potential DCOM InternetExplorer.Application DLL Hijack · test · critical · {"product":"windows","category":"file_event"}
- Potential DCOM InternetExplorer.Application DLL Hijack - Image Load · test · critical · {"product":"windows","category":"image_load"}
- BaaUpdate.exe Suspicious DLL Load · experimental · high · {"category":"image_load","product":"windows"}
- Suspicious WSMAN Provider Image Loads · test · medium · {"category":"image_load","product":"windows"}
- Suspicious Non PowerShell WSMAN COM Provider · test · medium · {"product":"windows","service":"powershell-classic"}
- Suspicious BitLocker Access Agent Update Utility Execution · experimental · high · {"category":"process_creation","product":"windows"}
- HackTool - Potential Impacket Lateral Movement Activity · stable · high · {"category":"process_creation","product":"windows"}
- MMC20 Lateral Movement · test · high · {"category":"process_creation","product":"windows"}
- MMC Spawning Windows Shell · test · high · {"category":"process_creation","product":"windows"}
- Potential Excel.EXE DCOM Lateral Movement Via ActivateMicrosoftApp · test · high · {"category":"process_creation","product":"windows"}
- Suspicious Speech Runtime Binary Child Process · experimental · high · {"category":"process_creation","product":"windows"}
Atlas deterministic concepts
No exact concept selected.
Anomaly models
No exact Atlas model in this snapshot.
ATT&CK analytic guidance
DET0285 Multi-Event Behavioral Detection for DCOM-Based Remote Code Execution
AN0791 Analytic 0791
A remote DCOM invocation by a privileged account using RPC (port 135), followed by abnormal process instantiation or module loading on the remote system indicative of code execution.
Connected ecosystem references
Linked tags
Simulation, tools and telemetry
Existing anomaly research
Pinned research references. No browser attack runner, live simulation result or validated detector is asserted. Source mappings and validation limits are preserved. ATT&CK / Atomic provenance · Detection provenance.