Detecting Macro Invoking ShellBrowserWindow COM Objects

Browse: 🏠 · Solutions · Connectors · Methods · Tables · Content · Parsers · ASIM Parsers · ASIM Products · 📊

Back to Content Index


This query detects a macro invoking ShellBrowserWindow COM Objects evade naive parent/child Office detection rules.

Attribute Value
Type Analytic Rule
Solution Endpoint Threat Protection Essentials
ID e7470b35-0128-4508-bfc9-e01cfb3c2eb7
Severity Medium
Status Available
Kind Scheduled
Tactics LateralMovement
Techniques T1021.003
Required Connectors SecurityEvents, WindowsSecurityEvents
Source View on GitHub

Tables Used

This content item queries data from the following tables:

Table Selection Criteria Transformations Ingestion API Lake-Only
Event EventID == "1"
EventLog == "Microsoft-Windows-Sysmon/Operational"
?

Browse: 🏠 · Solutions · Connectors · Methods · Tables · Content · Parsers · ASIM Parsers · ASIM Products · 📊

Back to Analytic Rules · Back to Endpoint Threat Protection Essentials