For the complete documentation index, see llms.txt. This page is also available as Markdown.

Rare DCOM RPC activity

Synopsis

Field
Value

Activation Period

14 Days

Training Period

30 Days

Test Period

N/A (single event)

Deduplication Period

1 Day

Required Data

Requires one of the following data sources: Palo Alto Networks Firewall EAL Logs OR XDR Agent with eXtended Threat Hunting (XTH)

Detector Tags

NDR Lateral Movement Analytics

ATT&CK Tactic

Lateral Movement (TA0008)

ATT&CK Technique

Remote Services: Distributed Component Object Model (T1021.003)

Severity

Informational

Description

The endpoint performed abnormal DCOM RPC activity to a remote host.

Attacker's Goals

  • Attackers may attempt to gain persistence or move laterally over the network by executing code on remote hosts using the DCOM RPC interface.

  • The DCOM RPC interface is used to remotely invoke registered COM applications on remote hosts.

Investigative actions

  • Review the action of the initiated COM application on the remote host.

  • Correlate the RPC call from the source host and understand which software initiated it.* Verify that this isn't IT activity.

Variations

Rare DCOM RPC activity

Synopsis

Field
Value

ATT&CK Tactic

Lateral Movement (TA0008)

ATT&CK Technique

Remote Services: Distributed Component Object Model (T1021.003)

Severity

Low

Description

The endpoint performed abnormal DCOM RPC activity to a remote host.

Attacker's Goals

  • Attackers may attempt to gain persistence or move laterally over the network by executing code on remote hosts using the DCOM RPC interface.

  • The DCOM RPC interface is used to remotely invoke registered COM applications on remote hosts.

Investigative actions

  • Review the action of the initiated COM application on the remote host.

  • Correlate the RPC call from the source host and understand which software initiated it.* Verify that this isn't IT activity.

Was this helpful?