Rare DCOM RPC activity
Synopsis
Activation Period
14 Days
Training Period
30 Days
Test Period
N/A (single event)
Deduplication Period
1 Day
Required Data
Requires one of the following data sources: Palo Alto Networks Firewall EAL Logs OR XDR Agent with eXtended Threat Hunting (XTH)
Detector Tags
NDR Lateral Movement Analytics
ATT&CK Tactic
Lateral Movement (TA0008)
ATT&CK Technique
Remote Services: Distributed Component Object Model (T1021.003)
Severity
Informational
Description
The endpoint performed abnormal DCOM RPC activity to a remote host.
Attacker's Goals
Attackers may attempt to gain persistence or move laterally over the network by executing code on remote hosts using the DCOM RPC interface.
The DCOM RPC interface is used to remotely invoke registered COM applications on remote hosts.
Investigative actions
Review the action of the initiated COM application on the remote host.
Correlate the RPC call from the source host and understand which software initiated it.* Verify that this isn't IT activity.
Variations
Was this helpful?
