1200KM / detection
T1559.001 Component Object Model — Detection Rules
Detection workspace for T1559.001 Component Object Model: 3 Sigma sources, 0 Atlas concepts and 0 anomaly models. No live detection validation.
Source-backed rule directory
- DNS Query Request By Regsvr32.EXE · test · medium · {"category":"dns_query","product":"windows"}
- Network Connection Initiated By Regsvr32.EXE · test · medium · {"category":"network_connection","product":"windows"}
- CMSTP Execution Process Access · stable · high · {"product":"windows","category":"process_access"}
Atlas deterministic concepts
No exact concept selected.
Anomaly models
No exact Atlas model in this snapshot.
ATT&CK analytic guidance
DET0224 Detect Abuse of Component Object Model (T1559.001)
AN0628 Analytic 0628
Detects anomalous use of COM objects for execution, such as Office applications spawning scripting engines, enumeration of COM interfaces via registry queries, or processes loading atypical DLLs through COM activation. Correlates process creation, module loads, and registry queries to flag suspicious COM-based code execution or persistence.
Connected ecosystem references
Linked tags
Simulation, tools and telemetry
Threat actor context
These are explicit actor-to-technique associations in the existing Threat Matrix snapshot, not attribution of an event or proof that a detector identifies the actor. No tool-to-actor relationship is inferred.
Existing anomaly research
Pinned research references. No browser attack runner, live simulation result or validated detector is asserted. Source mappings and validation limits are preserved. ATT&CK / Atomic provenance · Detection provenance.