Microsoft-Windows-DistributedCOM
68 events across 2 channels
Event ID 10000 — Unable to start a DCOM Server.
Message
Fields
| Name | Description |
|---|---|
param1 | — |
param2 | — |
param3 | — |
Event ID 10001 — Unable to start a DCOM Server: %3 as %4/%5.
Message
Fields
| Name | Description |
|---|---|
param1 | — |
param2 | — |
param3 | — |
param4 | — |
param5 | — |
Sigma Rules
- Local Privilege Escalation Indicator TabTip
Detects the invocation of TabTip via CLSID as seen when JuicyPotatoNG is used on a system in brute force mode
Event ID 10002 —
Fields
| Name | Description |
|---|---|
param1 | — |
param2 | — |
param3 | — |
param4 | — |
Event ID 10003 —
Fields
| Name | Description |
|---|---|
param1 | — |
param2 | — |
param3 | — |
param4 | — |
Event ID 10004 — DCOM got error ".
Message
Fields
| Name | Description |
|---|---|
param1 | — |
param2 | — |
param3 | — |
param4 | — |
Event ID 10005 — DCOM got error ".
Message
Fields
| Name | Description |
|---|---|
param1 | — |
param2 | — |
param3 | — |
param4 | — |
Event ID 10005 —
Fields
| Name | Description |
|---|---|
param1 | — |
param2 | — |
param3 | — |
param4 | — |
Example Event
system:
provider: Microsoft-Windows-DistributedCOM
guid: '{1B562E86-B7AA-4131-BADC-B6F3A001407E}'
event_source_name: DCOM
event_id: 10005
version: 0
level: 2
task: 0
opcode: 0
keywords: 9259400833873739776
time_created: '2019-04-27T21:04:43.704329Z'
event_record_id: 9256
correlation: {}
execution:
process_id: 756
thread_id: 4404
channel: System
computer: DESKTOP-JR78RLP
security:
user_id: S-1-5-18
event_data:
param1: '1068'
param2: netprofm
param3: Unavailable
param4: '{A47979D2-C419-11D9-A5B4-001185AD2B89}'
References
- Example event sourced from https://github.com/Yamato-Security/hayabusa-sample-evtx
Event ID 10006 — DCOM got error ".
Message
Fields
| Name | Description |
|---|---|
param1 | — |
param2 | — |
param3 | — |
Event ID 10007 —
Fields
| Name | Description |
|---|---|
param1 | — |
param2 | — |
Event ID 10008 — DCOM got error ".
Message
Fields
| Name | Description |
|---|---|
param1 | — |
param2 | — |
param3 | — |
param4 | — |
Event ID 10009 —
Fields
| Name | Description |
|---|---|
param1 | — |
__binLength | — |
binary | — |
Event ID 10010 — The server %1 did not register with DCOM within the required timeout.
Message
Fields
| Name | Description |
|---|---|
param1 | — |
Event ID 10010 —
Fields
| Name | Description |
|---|---|
param1 | — |
Example Event
system:
provider: Microsoft-Windows-DistributedCOM
guid: '{1B562E86-B7AA-4131-BADC-B6F3A001407E}'
event_source_name: DCOM
event_id: 10010
version: 0
level: 2
task: 0
opcode: 0
keywords: 9259400833873739776
time_created: '2023-10-25T22:55:19.214417+00:00'
event_record_id: 1460
correlation:
ActivityID: D5BBEBF4-0795-0001-900E-BCD59507DA01
execution:
process_id: 508
thread_id: 560
channel: System
computer: WinDevEval
security:
user_id: S-1-5-21-2533829718-189860685-2477588761-500
event_data:
param1: '{7D096C5F-AC08-4F1F-BEB7-5C22C517CE39}'
message: ''
References
- Example event sourced from https://github.com/NextronSystems/evtx-baseline
Event ID 10011 —
Fields
| Name | Description |
|---|---|
param1 | — |
Event ID 10012 —
Fields
| Name | Description |
|---|---|
param1 | — |
param2 | — |
param3 | — |
Event ID 10014 — The activation for CLSID %1 failed because remote activations for COM+ are disabled.
Message
Fields
| Name | Description |
|---|---|
param1 | — |
Event ID 10015 — The machine wide limit settings do not grant %1 %2 permission for the COM Server application with CLSID %3 and APPID %4 to the user %5\%6 SID (%7) ...
Message
Fields
| Name | Description |
|---|---|
param1 | — |
param2 | — |
param3 | — |
param4 | — |
param5 | — |
param6 | — |
param7 | — |
param8 | — |
param9 | — |
param10 | — |
Event ID 10016 — The %1 permission settings do not grant %2 %3 permission for the COM Server application with CLSID %4 and APPID %5 to the user %6\%7 SID (%8) from ...
Message
Fields
| Name | Description |
|---|---|
param1 | — |
param2 | — |
param3 | — |
param4 | — |
param5 | — |
param6 | — |
param7 | — |
param8 | — |
param9 | — |
param10 | — |
param11 | — |
Event ID 10016 —
Fields
| Name | Description |
|---|---|
param1 | — |
param2 | — |
param3 | — |
param4 | — |
param5 | — |
param6 | — |
param7 | — |
param8 | — |
param9 | — |
param10 | — |
param11 | — |
Example Event
system:
provider: Microsoft-Windows-DistributedCOM
guid: '{1B562E86-B7AA-4131-BADC-B6F3A001407E}'
event_source_name: DCOM
event_id: 10016
version: 0
level: 3
task: 0
opcode: 0
keywords: 9259400833873739776
time_created: '2023-11-05T23:54:13.816805+00:00'
event_record_id: 2034
correlation:
ActivityID: E4DB489E-1037-0003-B8CC-E0E43710DA01
execution:
process_id: 8
thread_id: 10920
channel: System
computer: WinDev2310Eval
security:
user_id: S-1-5-21-1992711665-1655669231-58201500-1000
event_data:
param1: application-specific
param2: Local
param3: Activation
param4: '{2593F8B9-4EAF-457C-B68A-50F6B8EA6B54}'
param5: '{15C20B67-12E7-4BB6-92BB-7AFF07997402}'
param6: WINDEV2310EVAL
param7: User
param8: S-1-5-21-1992711665-1655669231-58201500-1000
param9: LocalHost (Using LRPC)
param10: Unavailable
param11: Unavailable
message: ''
References
- Example event sourced from https://github.com/NextronSystems/evtx-baseline
Event ID 10017 — The %1 permission settings do not grant %2 access permission to the COM Server application %3 with APPID %4 to the user %5\%6 SID (%7) from address...
Message
Fields
| Name | Description |
|---|---|
param1 | — |
param2 | — |
param3 | — |
param4 | — |
param5 | — |
param6 | — |
param7 | — |
param8 | — |
param9 | — |
param10 | — |
Event ID 10018 — The application-specific permission settings do not grant %1 access permission to the COM Server application %2 with APPID %3 to the user %4\%5 SID...
Message
Fields
| Name | Description |
|---|---|
param1 | — |
param2 | — |
param3 | — |
param4 | — |
param5 | — |
param6 | — |
param7 | — |
param8 | — |
param9 | — |
Event ID 10019 — The machine wide limit settings do not grant %1 access permission to the COM Server application %2 with APPID %3 to the user %4\%5 SID (%6) from ad...
Message
Fields
| Name | Description |
|---|---|
param1 | — |
param2 | — |
param3 | — |
param4 | — |
param5 | — |
param6 | — |
param7 | — |
param8 | — |
param9 | — |
Event ID 10020 — The machine wide %1 %2 security descriptor is invalid.
Message
Fields
| Name | Description |
|---|---|
param1 | — |
param2 | — |
Event ID 10021 — The launch and activation security descriptor for the COM Server application with APPID %1 is invalid.
Message
Fields
| Name | Description |
|---|---|
param1 | — |
Event ID 10022 — The %1 access security descriptor for the COM Server application %2 with APPID %3 is invalid.
Message
Fields
| Name | Description |
|---|---|
param1 | — |
param2 | — |
param3 | — |
Event ID 10023 — The application-specific access security descriptor for the COM Server application %1 with APPID %2 is invalid.
Message
Fields
| Name | Description |
|---|---|
param1 | — |
param2 | — |
Event ID 10024 — The machine wide group policy %1 Limits security descriptor is invalid.
Message
Fields
| Name | Description |
|---|---|
param1 | — |
Event ID 10026 —
Fields
| Name | Description |
|---|---|
param1 | — |
param2 | — |
param3 | — |
Event ID 10027 — The machine wide limit settings do not grant %1 %2 permission for COM Server applications to the user %3\%4 SID (%5) from address %6 running in the...
Message
Fields
| Name | Description |
|---|---|
param1 | — |
param2 | — |
param3 | — |
param4 | — |
param5 | — |
param6 | — |
param7 | — |
param8 | — |
Event ID 10028 — DCOM was unable to communicate with the computer %1 using any of the configured protocols; requested by PID %2 (%3), while activating CLSID %4.
Message
Fields
| Name | Description |
|---|---|
param1 | — |
param2 | — |
param3 | — |
param4 | — |
__binLength | — |
binary | — |
Event ID 10029 — The activation of the CLSID %1 timed out waiting for the service %2 to stop.
Message
Fields
| Name | Description |
|---|---|
param1 | — |
param2 | — |
Event ID 10030 — Unable to start a COM Server for debugging.
Message
Fields
| Name | Description |
|---|---|
param1 | — |
param2 | — |
param3 | — |
Event ID 10031 — An unmarshaling policy check was performed when unmarshaling a custom marshaled object and the class %1 was rejected.
Message
Fields
| Name | Description |
|---|---|
param1 | — |
Event ID 10032 — An unmarshaling policy check was performed when unmarshaling a custom inproc handler and the class %1 was rejected.
Message
Fields
| Name | Description |
|---|---|
param1 | — |
Event ID 10033 — An unmarshaling policy check was performed when unmarshaling a COM+ envoy context property and the class %1 was rejected.
Message
Fields
| Name | Description |
|---|---|
param1 | — |
Event ID 10034 — An unmarshaling policy check was performed due to CLSCTX_NO_CUSTOM_MARSHAL and the class %1 was rejected.
Message
Fields
| Name | Description |
|---|---|
param1 | — |
Event ID 10035 — The COM standard marshaler was unable to fix a mismatch between the IID %1 provided by the server and the IID %2 requested by the client, with hand...
Message
Fields
| Name | Description |
|---|---|
ProvidedIid | — |
RequestedIid | — |
HandlerClsid | — |
HRESULT | — |
Event ID 10036 — The server-side authentication level policy does not allow the user %1\%2 SID (%3) from address %4 to activate DCOM server.
Message
Fields
| Name | Description |
|---|---|
DomainName | — |
UserName | — |
SID | — |
ClientIPAddress | — |
Event ID 10037 — Application %1 with PID %2 is requesting to activate CLSID %3 on computer %4 with explicitly set authentication level at %5.
Message
Fields
| Name | Description |
|---|---|
ApplicationName | — |
PID | — |
CLSID | — |
ComputerName | — |
ActivationAuthenticationLevel | — |
Event ID 10038 — Application %1 with PID %2 is requesting to activate CLSID %3 on computer %4 with default activation authentication level at %5.
Message
Fields
| Name | Description |
|---|---|
ApplicationName | — |
PID | — |
CLSID | — |
ComputerName | — |
ActivationAuthenticationLevel | — |
Event ID 1073751850 — The COM sub system is suppressing duplicate event log entries for a duration of %1 seconds.
Message
Fields
| Name | Description |
|---|---|
param1 | — |
param2 | — |
param3 | — |
Event ID 3221235472 — Unable to start a DCOM Server: {param3}.
Message
Fields
| Name | Description |
|---|---|
param3 | — |
param2 | — |
param1 | — |
Event ID 3221235473 — Unable to start a DCOM Server: {param3} as {param4}/{param5}.
Message
Fields
| Name | Description |
|---|---|
param3 | — |
param4 | — |
param5 | — |
param2 | — |
param1 | — |
Event ID 3221235474 — Access denied attempting to launch a DCOM Server.
Message
Fields
| Name | Description |
|---|---|
param1 | — |
param2 | — |
param3 | — |
param4 | — |
Event ID 3221235475 — Access denied attempting to launch a DCOM Server using DefaultLaunchPermssion.
Message
Fields
| Name | Description |
|---|---|
param1 | — |
param2 | — |
param3 | — |
param4 | — |
Event ID 3221235476 — DCOM got error '.
Message
Fields
| Name | Description |
|---|---|
param1 | — |
param2 | — |
param3 | — |
param4 | — |
Event ID 3221235477 — DCOM got error '.
Message
Fields
| Name | Description |
|---|---|
param1 | — |
param2 | — |
param3 | — |
param4 | — |
Event ID 3221235478 — DCOM got error '.
Message
Fields
| Name | Description |
|---|---|
param1 | — |
param2 | — |
param3 | — |
Event ID 3221235479 — DCOM got error ".
Message
Fields
| Name | Description |
|---|---|
param1 | — |
param2 | — |
Event ID 3221235480 — DCOM got error '.
Message
Fields
| Name | Description |
|---|---|
param1 | — |
param2 | — |
param3 | — |
param4 | — |
Event ID 3221235481 — DCOM was unable to communicate with the computer %1 using any of the configured protocols.
Message
Fields
| Name | Description |
|---|---|
param1 | — |
binary | — |
Event ID 3221235482 — The server {param1} did not register with DCOM within the required timeout.
Message
Fields
| Name | Description |
|---|---|
param1 | — |
Event ID 3221235483 — The server %1 could not be contacted to establish the connection to the client.
Message
Fields
| Name | Description |
|---|---|
param1 | — |
Event ID 3221235484 — There is an assertion failure in DCOM.
Message
Fields
| Name | Description |
|---|---|
param1 | — |
param2 | — |
param3 | — |
Event ID 3221235486 — The activation for CLSID {param1} failed because remote activations for COM+ are disabled.
Message
Fields
| Name | Description |
|---|---|
param1 | — |
Event ID 3221235487 — The machine wide limit settings do not grant {param1} {param2} permission for the COM Server application with CLSID {param3} and APPID {param4} to ...
Message
Fields
| Name | Description |
|---|---|
param1 | — |
param2 | — |
param3 | — |
param4 | — |
param5 | — |
param6 | — |
param7 | — |
param8 | — |
Event ID 3221235488 — The {param1} permission settings do not grant {param2} {param3} permission for the COM Server application with CLSID {param4} and APPID {param5} to...
Message
Fields
| Name | Description |
|---|---|
param1 | — |
param2 | — |
param3 | — |
param4 | — |
param5 | — |
param6 | — |
param7 | — |
param8 | — |
param9 | — |
Event ID 3221235489 — The {param1} permission settings do not grant {param2} access permission to the COM Server application {param3} with APPID {param4} to the user {pa...
Message
Fields
| Name | Description |
|---|---|
param1 | — |
param2 | — |
param3 | — |
param4 | — |
param5 | — |
param6 | — |
param7 | — |
param8 | — |
Event ID 3221235490 — The application-specific permission settings do not grant {param1} access permission to the COM Server application {param2} with APPID {param3} to ...
Message
Fields
| Name | Description |
|---|---|
param1 | — |
param2 | — |
param3 | — |
param4 | — |
param5 | — |
param6 | — |
param7 | — |
Event ID 3221235491 — The machine wide limit settings do not grant {param1} access permission to the COM Server application {param2} with APPID {param3} to the user {par...
Message
Fields
| Name | Description |
|---|---|
param1 | — |
param2 | — |
param3 | — |
param4 | — |
param5 | — |
param6 | — |
param7 | — |
Event ID 3221235492 — The machine wide {param1} {param2} security descriptor is invalid.
Message
Fields
| Name | Description |
|---|---|
param1 | — |
param2 | — |
Event ID 3221235493 — The launch and activation security descriptor for the COM Server application with APPID {param1} is invalid.
Message
Fields
| Name | Description |
|---|---|
param1 | — |
Event ID 3221235494 — The {param1} access security descriptor for the COM Server application {param2} with APPID %3 is invalid.
Message
Fields
| Name | Description |
|---|---|
param1 | — |
param2 | — |
Event ID 3221235495 — The application-specific access security descriptor for the COM Server application {param1} with APPID %2 is invalid.
Message
Fields
| Name | Description |
|---|---|
param1 | — |
Event ID 3221235496 — The machine wide group policy {param1} Limits security descriptor is invalid.
Message
Fields
| Name | Description |
|---|---|
param1 | — |
Event ID 3221235499 — The machine wide limit settings do not grant {param1} {param2} permission for COM Server applications to the user {param3}\{param4} SID ({param5}) ...
Message
Fields
| Name | Description |
|---|---|
param1 | — |
param2 | — |
param3 | — |
param4 | — |
param5 | — |
param6 | — |
Event ID 3221235501 — DCOM started the service {param1} with arguments '{param2}' in order to run the server:{param3}.
Message
Fields
| Name | Description |
|---|---|
param1 | — |
param2 | — |
param3 | — |
Event ID 3221235507 — The COM standard marshaler was unable to fix a mismatch between the IID {ProvidedIid} provided by the server and the IID {RequestedIid} requested b...
Message
Fields
| Name | Description |
|---|---|
ProvidedIid | — |
RequestedIid | — |
HandlerClsid | — |
HRESULT | — |