Malicious Impacket DCOMexec Privilege Abuse via MMC (via security)

PremiumReviewedSigma · High · v1
Product
windows
Service
security
Author
HuntRule
Published
2026-08-31
Updated
2026-08-31

ATT&CK techniques

Lateral Movement
  1. Recon

  2. Resource Dev

  3. Initial Access

  4. Execution

  5. Persistence

  6. Priv Esc

  7. Defense Evasion

  8. Cred Access

  9. Discovery

  10. Collection

  11. C2

  12. Exfiltration

  13. Impact

What it detects

This rule detects execute the Impacket DCOMexec tool in order to abuse DCOM services.

Related detections9 linkedT1021.003 — drag to rearrange
Malicious Impacket DCOMexec Process Abuse via MMC (via process_creation)
DCOM Lateral Movement - Via MMC20 (via powershell)
Suspicious DLL Payload Dropped Under Non-Standard Assembly Directory (via file_event)
Windows SpeechRuntime.exe Child Process Creation
Windows: Detect Suspicious DLL Loads by BaaUpdate.exe from Publicly Writable Paths
Windows: Detect baaupdate.exe Spawning Scripting, Admin, or LOLBin Child Processes
Windows Process Creation: Excel DCOM Child Processes Linked to ActivateMicrosoftApp
RPC Firewall detects remote DCOM/WMI-related RPC operations via specified interface UUIDs
Windows DCOM InternetExplorer.Application iertutil.dll DLL Hijack Suspicion
Malicious Impacket DCOMexec Privilege Abuse via MMC (via security)
Pivot detection · T1021.003 · 9 related

Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.