{"id":"T1559.001","name":"Component Object Model","url":"https://attack.mitre.org/techniques/T1559/001","tactics":["execution"],"platforms":["Windows"],"live":true,"revoked":false,"deprecated":false,"revoked_by":null,"detection_strategies":[{"id":"DET0224","stix_id":"x-mitre-detection-strategy--96c3e267-9dde-45cb-b700-e27c1a672cf8","name":"Detect Abuse of Component Object Model (T1559.001)","url":"https://attack.mitre.org/detectionstrategies/DET0224","analytics":[{"id":"AN0628","stix_id":"x-mitre-analytic--8a7a7e80-c28e-42b2-a222-c1d75932c986","name":"Analytic 0628","description":"Detects anomalous use of COM objects for execution, such as Office applications spawning scripting engines, enumeration of COM interfaces via registry queries, or processes loading atypical DLLs through COM activation. Correlates process creation, module loads, and registry queries to flag suspicious COM-based code execution or persistence.","url":"https://attack.mitre.org/detectionstrategies/DET0224#AN0628","platforms":["Windows"],"log_source_references":[{"name":"WinEventLog:Sysmon","channel":"EventCode=1","data_component":"DC0032","data_component_name":"Process Creation","log_source_slug":"wineventlog-sysmon"},{"name":"WinEventLog:Sysmon","channel":"EventCode=7","data_component":"DC0016","data_component_name":"Module Load","log_source_slug":"wineventlog-sysmon"},{"name":"WinEventLog:Security","channel":"EventCode=4663, 4670, 4656","data_component":"DC0050","data_component_name":"Windows Registry Key Access","log_source_slug":"wineventlog-security"}],"mutable_elements":[{"field":"COMObjectAllowList","description":"Legitimate COM CLSIDs and ProgIDs used by enterprise applications, to reduce false positives."},{"field":"ParentProcessExclusions","description":"Expected parent-child process relationships (e.g., explorer.exe spawning dllhost.exe)."},{"field":"TimeWindow","description":"Threshold for correlating COM object execution with subsequent process creation or DLL load."}],"live":true,"detection_strategies":["DET0224"],"techniques":["T1559.001"]}],"live":true,"version":"1.0","techniques":["T1559.001"]}],"sigma_rules":[{"id":"36e037c4-c228-4866-b6a3-48eb292b9955","title":"DNS Query Request By Regsvr32.EXE","author":"Dmitriy Lifanov, oscd.community","status":"test","level":"medium","date":"2019-10-25","modified":"2023-09-18","description":"Detects DNS queries initiated by \"Regsvr32.exe\"","references":["https://pentestlab.blog/2017/05/11/applocker-bypass-regsvr32/","https://oddvar.moe/2017/12/13/applocker-case-study-how-insecure-is-it-really-part-1/"],"logsource":{"product":"windows","category":"dns_query"},"tags":["attack.execution","attack.stealth","attack.t1559.001","attack.t1218.010"],"path":"rules/windows/dns_query/dns_query_win_regsvr32_dns_query.yml","techniques":["T1559.001","T1218.010"],"cves":[]},{"id":"3b4b232a-af90-427c-a22f-30b0c0837b95","title":"CMSTP Execution Process Access","author":"Nik Seetharaman","status":"stable","level":"high","date":"2018-07-16","modified":"2021-06-27","description":"Detects various indicators of Microsoft Connection Manager Profile Installer execution","references":["https://web.archive.org/web/20190720093911/http://www.endurant.io/cmstp/detecting-cmstp-enabled-code-execution-and-uac-bypass-with-sysmon/"],"logsource":{"product":"windows","category":"process_access"},"tags":["attack.stealth","attack.t1218.003","attack.execution","attack.t1559.001","attack.g0069","attack.g0080","car.2019-04-001"],"path":"rules/windows/process_access/proc_access_win_cmstp_execution_by_access.yml","techniques":["T1218.003","T1559.001"],"cves":[]},{"id":"c7e91a02-d771-4a6d-a700-42587e0b1095","title":"Network Connection Initiated By Regsvr32.EXE","author":"Dmitriy Lifanov, oscd.community","status":"test","level":"medium","date":"2019-10-25","modified":"2023-09-18","description":"Detects a network connection initiated by \"Regsvr32.exe\"","references":["https://pentestlab.blog/2017/05/11/applocker-bypass-regsvr32/","https://oddvar.moe/2017/12/13/applocker-case-study-how-insecure-is-it-really-part-1/"],"logsource":{"product":"windows","category":"network_connection"},"tags":["attack.execution","attack.stealth","attack.t1559.001","attack.t1218.010"],"path":"rules/windows/network_connection/net_connection_win_regsvr32_network_activity.yml","techniques":["T1559.001","T1218.010"],"cves":[]},{"id":"cfed2f44-16df-4bf3-833a-79405198b277","title":"Dllhost.EXE Initiated Network Connection To Non-Local IP Address","author":"bartblaze","status":"test","level":"medium","date":"2020-07-13","modified":"2024-07-16","description":"Detects Dllhost.EXE initiating a network connection to a non-local IP address.\nAside from Microsoft own IP range that needs to be excluded. Network communication from Dllhost will depend entirely on the hosted DLL.\nAn initial baseline is recommended before deployment.\n","references":["https://redcanary.com/blog/child-processes/","https://nasbench.medium.com/what-is-the-dllhost-exe-process-actually-running-ef9fe4c19c08"],"logsource":{"product":"windows","category":"network_connection"},"tags":["attack.stealth","attack.t1218","attack.execution","attack.t1559.001","detection.threat-hunting"],"path":"rules-threat-hunting/windows/network_connection/net_connection_win_dllhost_non_local_ip.yml","techniques":["T1218","T1559.001"],"cves":[]}],"kev_cves":[],"_built":"2026-08-23 05:47 UTC","_attack_version":"19.2","_sigma_commit":"da9bb07d642a2826e89702445d32c795209ec108"}