Component Object Model
Adversaries may use the Windows Component Object Model (COM) for local code execution. COM is an inter-process communication (IPC) component of the native Windows application programming interface (API) that enables interaction between software objects, or executable code that implements one or more interfaces.(Citation: Fireeye Hunting COM June 2019) Through COM, a client object can call methods of server objects, which are typically binary Dynamic Link Libraries (DLL) or executables (EXE).(Cit...
BY SOURCE
PROCEDURES (11)
Auto-extracted: 3 detections for lateral
Auto-extracted: 3 detections for bypass
Auto-extracted: 2 detections for registry
Auto-extracted: 1 detections for process access monitoring
Auto-extracted: 1 detections for office
Auto-extracted: 1 detections for suspicious
Auto-extracted: 1 detections for persist
Auto-extracted: 1 detections for unusual
Auto-extracted: 1 detections for unusual
Auto-extracted: 1 detections for general monitoring
Auto-extracted: 1 detections for network connection monitoring