Executive Summary
Distributed Component Object Model (DCOM) is a native Windows mechanism used for inter-process communication over a network. While legitimate for administrative tasks, attackers frequently abuse it for lateral movement because it allows for remote code execution using trusted, signed Microsoft binaries, effectively bypassing traditional application whitelisting and file-based detection.
The attack typically begins with credential theft, followed by an RPC connection over TCP port 135 to a target machine. Once authenticated, the attacker instantiates a COM object (such as MMC20.Application) via its Class ID (CLSID) and invokes methods like ExecuteShellCommand. This results in a legitimate process (e.g., mmc.exe) spawning a malicious child process like PowerShell or CMD, residing entirely within trusted system workflows.
This technique is highly effective for stealthy movement within a domain. Organizations should focus on correlating network logon events with suspicious parent-child process relationships and restricting DCOM remote activation permissions to mitigate this risk.
