2.9 KiB
title, excerpt, categories, last_modified_at, toc, tags
| title | excerpt | categories | last_modified_at | toc | tags | |||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| Powershell Execute COM Object | Component Object Model Hijacking |
|
2021-08-10 | true |
|
Description
This search is to detect a COM CLSID execution through powershell. This technique was seen in several adversaries and malware like ransomware conti where it has a feature to execute command using COM Object. This technique may use by network operator at some cases but a good indicator if some application want to gain privilege escalation or bypass uac.
- Product: Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud
- Datamodel: Endpoint
- Last Updated: 2021-08-10
- Author: Teoderick Contreras, Splunk
ATT&CK
| ID | Technique | Tactic |
|---|---|---|
| T1546.015 | Component Object Model Hijacking | Privilege Escalation, Persistence |
Search
`powershell` EventCode=4104 Message = "*CreateInstance([type]::GetTypeFromCLSID*" OR Message = "*CreateInstance([Type]::GetTypeFromProgID*"
| stats count min(_time) as firstTime max(_time) as lastTime by EventCode Message ComputerName User
| `security_content_ctime(firstTime)`
| `security_content_ctime(lastTime)`
| `powershell_execute_com_object_filter`
Associated Analytic Story
How To Implement
To successfully implement this search, you need to be ingesting logs with the process name, parent process, and command-line executions from your endpoints. If you are using Sysmon, you must have at least version 6.0.4 of the Sysmon TA.
Required field
- _time
Kill Chain Phase
- Exploitation
Known False Positives
network operrator may use this command.
RBA
| Risk Score | Impact | Confidence |
|---|---|---|
| 5.0 | 10 | 50 |
Reference
Test Dataset
Replay any dataset to Splunk Enterprise by using our replay.py tool or the UI.
Alternatively you can replay a dataset into a Splunk Attack Range
version: 1