Abusing Windows DCOM for Lateral Movement
Score: 8/10

Abusing Windows DCOM for Lateral Movement

Attackers leverage the Windows Distributed Component Object Model (DCOM) to execute remote commands via trusted binaries like mmc.exe and excel.exe.

Executive Summary

Distributed Component Object Model (DCOM) is a native Windows mechanism used for inter-process communication over a network. While legitimate for administrative tasks, attackers frequently abuse it for lateral movement because it allows for remote code execution using trusted, signed Microsoft binaries, effectively bypassing traditional application whitelisting and file-based detection.

The attack typically begins with credential theft, followed by an RPC connection over TCP port 135 to a target machine. Once authenticated, the attacker instantiates a COM object (such as MMC20.Application) via its Class ID (CLSID) and invokes methods like ExecuteShellCommand. This results in a legitimate process (e.g., mmc.exe) spawning a malicious child process like PowerShell or CMD, residing entirely within trusted system workflows.

This technique is highly effective for stealthy movement within a domain. Organizations should focus on correlating network logon events with suspicious parent-child process relationships and restricting DCOM remote activation permissions to mitigate this risk.

Key Details

Threat Name

DCOM-Based Lateral Movement

Affects

—

Adversary

—

Malware/Tools

None identified

Report Score

8out of 10
Quality Score
Good
IOC Quality6
TTP Details9
Detection Guidance8
Enterprise Relevance9
Clarity & Structure9
Technical Depth8

Sources