Microsoft-Windows-DistributedCOM
69 events across 2 channels
Event ID 10000 — Unable to start a DCOM Server: param3.
Event ID 10001 — Unable to start a DCOM Server: param3 as param4/param5.
Description
Unable to start a DCOM Server: param3 as param4/param5. The error.
Message #
Fields #
| Name | Description |
|---|---|
param1 UnicodeString | — |
param2 UnicodeString | — |
param3 UnicodeString | — |
param4 UnicodeString | — |
param5 UnicodeString | — |
Detection Rules #
View all rules referencing this event →
Sigma # view in reference
- Local Privilege Escalation Indicator TabTip source high: Detects the invocation of TabTip via CLSID as seen when JuicyPotatoNG is used on a system in brute force mode
Event ID 10002 —
Fields #
| Name | Description |
|---|---|
param1 UnicodeString | — |
param2 UnicodeString | — |
param3 UnicodeString | — |
param4 UnicodeString | — |
Event ID 10003 —
Fields #
| Name | Description |
|---|---|
param1 UnicodeString | — |
param2 UnicodeString | — |
param3 UnicodeString | — |
param4 UnicodeString | — |
Event ID 10004 — DCOM got error "param1" and was unable to logon param2\param3 in order to run the server: param4.
Event ID 10005 — DCOM got error "param1" attempting to start the service param2 with arguments "param3" in order to run the server: param4.
Event ID 10005 —
#Description
DCOM got error "param1" attempting to start the service param2 with arguments "param3" in order to run the server.
Fields #
| Name | Description |
|---|---|
param1 | — |
param2 | — |
param3 | — |
param4 | — |
Example Event #
{
"system": {
"provider": "Microsoft-Windows-DistributedCOM",
"guid": "{1B562E86-B7AA-4131-BADC-B6F3A001407E}",
"event_source_name": "DCOM",
"event_id": 10005,
"version": 0,
"level": 2,
"task": 0,
"opcode": 0,
"keywords": 9259400833873739776,
"time_created": "2019-04-27T21:04:43.704329Z",
"event_record_id": 9256,
"correlation": {},
"execution": {
"process_id": 756,
"thread_id": 4404
},
"channel": "System",
"computer": "DESKTOP-JR78RLP",
"security": {
"user_id": "S-1-5-18"
}
},
"event_data": {
"param1": "1068",
"param2": "netprofm",
"param3": "Unavailable",
"param4": "{A47979D2-C419-11D9-A5B4-001185AD2B89}"
}
}
References #
- Example event sourced from https://github.com/Yamato-Security/hayabusa-sample-evtx
Event ID 10006 — DCOM got error "param1" from the computer param2 when attempting to activate the server: param3.
Event ID 10007 —
Fields #
| Name | Description |
|---|---|
param1 UnicodeString | — |
param2 UnicodeString | — |
Event ID 10008 — DCOM got error "param1" from the computer param2 when attempting to the server.
Event ID 10009 —
Fields #
| Name | Description |
|---|---|
param1 UnicodeString | — |
__binLength UInt32 | — |
binary Binary | — |
Event ID 10010 — The server param1 did not register with DCOM within the required timeout.
Event ID 10010 —
#Description
The server did not register with DCOM within the required timeout.
Fields #
| Name | Description |
|---|---|
param1 | — |
Example Event #
{
"system": {
"provider": "Microsoft-Windows-DistributedCOM",
"guid": "{1B562E86-B7AA-4131-BADC-B6F3A001407E}",
"event_source_name": "DCOM",
"event_id": 10010,
"version": 0,
"level": 2,
"task": 0,
"opcode": 0,
"keywords": 9259400833873739776,
"time_created": "2023-10-25T22:55:19.214417+00:00",
"event_record_id": 1460,
"correlation": {
"ActivityID": "D5BBEBF4-0795-0001-900E-BCD59507DA01"
},
"execution": {
"process_id": 508,
"thread_id": 560
},
"channel": "System",
"computer": "WinDevEval",
"security": {
"user_id": "S-1-5-21-2533829718-189860685-2477588761-500"
}
},
"event_data": {
"param1": "{7D096C5F-AC08-4F1F-BEB7-5C22C517CE39}"
},
"message": ""
}
References #
- Example event sourced from https://github.com/NextronSystems/evtx-baseline
Event ID 10011 —
Fields #
| Name | Description |
|---|---|
param1 UnicodeString | — |
Event ID 10012 —
Fields #
| Name | Description |
|---|---|
param1 UnicodeString | — |
param2 UnicodeString | — |
param3 UnicodeString | — |
Event ID 10014 — The activation for CLSID param1 failed because remote activations for COM+ are disabled.
Event ID 10015 — The machine wide limit settings do not grant param1 param2 permission for the COM Server application with CLSID.
Description
The machine wide limit settings do not grant param1 param2 permission for the COM Server application with CLSID.
Message #
Fields #
| Name | Description |
|---|---|
param1 UnicodeString | — |
param2 UnicodeString | — |
param3 UnicodeString | — |
param4 UnicodeString | — |
param5 UnicodeString | — |
param6 UnicodeString | — |
param7 UnicodeString | — |
param8 UnicodeString | — |
param9 UnicodeString | — |
param10 UnicodeString | — |
Event ID 10016 — The param1 permission settings do not grant param2 param3 permission for the COM Server application with CLSID.
Description
The param1 permission settings do not grant param2 param3 permission for the COM Server application with CLSID.
Message #
Fields #
| Name | Description |
|---|---|
param1 UnicodeString | — |
param2 UnicodeString | — |
param3 UnicodeString | — |
param4 UnicodeString | — |
param5 UnicodeString | — |
param6 UnicodeString | — |
param7 UnicodeString | — |
param8 UnicodeString | — |
param9 UnicodeString | — |
param10 UnicodeString | — |
param11 UnicodeString | — |
Event ID 10016 —
#Description
The permission settings do not grant permission for the COM Server application with CLSID.
Fields #
| Name | Description |
|---|---|
param1 | — |
param2 | — |
param3 | — |
param4 | — |
param5 | — |
param6 | — |
param7 | — |
param8 | — |
param9 | — |
param10 | — |
param11 | — |
Example Event #
{
"system": {
"provider": "Microsoft-Windows-DistributedCOM",
"guid": "{1B562E86-B7AA-4131-BADC-B6F3A001407E}",
"event_source_name": "DCOM",
"event_id": 10016,
"version": 0,
"level": 3,
"task": 0,
"opcode": 0,
"keywords": 9259400833873739776,
"time_created": "2023-11-05T23:54:13.816805+00:00",
"event_record_id": 2034,
"correlation": {
"ActivityID": "E4DB489E-1037-0003-B8CC-E0E43710DA01"
},
"execution": {
"process_id": 8,
"thread_id": 10920
},
"channel": "System",
"computer": "WinDev2310Eval",
"security": {
"user_id": "S-1-5-21-1992711665-1655669231-58201500-1000"
}
},
"event_data": {
"param1": "application-specific",
"param2": "Local",
"param3": "Activation",
"param4": "{2593F8B9-4EAF-457C-B68A-50F6B8EA6B54}",
"param5": "{15C20B67-12E7-4BB6-92BB-7AFF07997402}",
"param6": "WINDEV2310EVAL",
"param7": "User",
"param8": "S-1-5-21-1992711665-1655669231-58201500-1000",
"param9": "LocalHost (Using LRPC)",
"param10": "Unavailable",
"param11": "Unavailable"
},
"message": ""
}
References #
- Example event sourced from https://github.com/NextronSystems/evtx-baseline
Event ID 10017 — The param1 permission settings do not grant param2 access permission to the COM Server application param3 with APPID.
Description
The param1 permission settings do not grant param2 access permission to the COM Server application param3 with APPID.
Message #
Fields #
| Name | Description |
|---|---|
param1 UnicodeString | — |
param2 UnicodeString | — |
param3 UnicodeString | — |
param4 UnicodeString | — |
param5 UnicodeString | — |
param6 UnicodeString | — |
param7 UnicodeString | — |
param8 UnicodeString | — |
param9 UnicodeString | — |
param10 UnicodeString | — |
Event ID 10018 — The application-specific permission settings do not grant param1 access permission to the COM Server application param2 with APPID.
Description
The application-specific permission settings do not grant param1 access permission to the COM Server application param2 with APPID.
Message #
Fields #
| Name | Description |
|---|---|
param1 UnicodeString | — |
param2 UnicodeString | — |
param3 UnicodeString | — |
param4 UnicodeString | — |
param5 UnicodeString | — |
param6 UnicodeString | — |
param7 UnicodeString | — |
param8 UnicodeString | — |
param9 UnicodeString | — |
Event ID 10019 — The machine wide limit settings do not grant param1 access permission to the COM Server application param2 with APPID.
Description
The machine wide limit settings do not grant param1 access permission to the COM Server application param2 with APPID.
Message #
Fields #
| Name | Description |
|---|---|
param1 UnicodeString | — |
param2 UnicodeString | — |
param3 UnicodeString | — |
param4 UnicodeString | — |
param5 UnicodeString | — |
param6 UnicodeString | — |
param7 UnicodeString | — |
param8 UnicodeString | — |
param9 UnicodeString | — |
Event ID 10020 — The machine wide param1 param2 security descriptor is invalid.
Event ID 10021 — The launch and activation security descriptor for the COM Server application with APPID.
Event ID 10022 — The param1 access security descriptor for the COM Server application param2 with APPID.
Event ID 10023 — The application-specific access security descriptor for the COM Server application param1 with APPID.
Event ID 10024 — The machine wide group policy param1 Limits security descriptor is invalid.
Event ID 10026 —
Fields #
| Name | Description |
|---|---|
param1 UnicodeString | — |
param2 UnicodeString | — |
param3 UnicodeString | — |
Event ID 10027 — The machine wide limit settings do not grant param1 param2 permission for COM Server applications to the user param3\param4 SID (param5) from address param6 running in the...
Event ID 10028 — DCOM was unable to communicate with the computer param1 using any of the configured protocols; requested by PID param2 (param3), while activating CLSID param4.
Description
DCOM was unable to communicate with the computer param1 using any of the configured protocols; requested by PID param2 (param3), while activating CLSID param4.
Message #
Fields #
| Name | Description |
|---|---|
param1 UnicodeString | — |
param2 UnicodeString | — |
param3 UnicodeString | — |
param4 UnicodeString | — |
__binLength UInt32 | — |
binary Binary | — |
Event ID 10028 —
Description
DCOM was unable to communicate with the computer using any of the configured protocols; requested by PID (), while activating CLSID .
Fields #
| Name | Description |
|---|---|
param1 | — |
param2 | — |
param3 | — |
param4 | — |
Binary | — |
Example Event #
{
"system": {
"provider": "Microsoft-Windows-DistributedCOM",
"guid": "{1B562E86-B7AA-4131-BADC-B6F3A001407E}",
"event_source_name": "DCOM",
"event_id": 10028,
"version": 0,
"level": 2,
"task": 0,
"opcode": 0,
"keywords": 9259400833873739776,
"time_created": "2026-03-13T23:06:00.558843+00:00",
"event_record_id": 12279,
"correlation": {
"ActivityID": "2A8C090C-ABB5-42FC-ABDE-C1146B129851"
},
"execution": {
"process_id": 1212,
"thread_id": 6732
},
"channel": "System",
"computer": "LAB-DC01.ludus.domain",
"security": {
"user_id": "S-1-5-21-1006758700-2167138679-1475694448-1105"
}
},
"event_data": {
"param1": "DC1",
"param2": " 287c",
"param3": "C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe",
"param4": "{8BC3F05E-D86B-11D0-A075-00C04FB68820}",
"Binary": "3C5265636F726423313A20436F6D70757465723D286E756C6C293B5069643D313231323B332F31332F323032362032333A363A303A3535383B5374617475733D313732323B47656E636F6D703D323B4465746C6F633D313731303B466C6167733D303B506172616D733D313B7B506172616D23303A307D3E3C5265636F726423323A20436F6D70757465723D286E756C6C293B5069643D313231323B332F31332F323032362032333A363A303A3535383B5374617475733D313732323B47656E636F6D703D31383B4465746C6F633D313434323B466C6167733D303B506172616D733D313B7B506172616D23303A4443317D3E3C5265636F726423333A20436F6D70757465723D286E756C6C293B5069643D313231323B332F31332F323032362032333A363A303A3535383B5374617475733D313732323B47656E636F6D703D31383B4465746C6F633D3332323B466C6167733D303B506172616D733D303B3E3C5265636F726423343A20436F6D70757465723D286E756C6C293B5069643D313231323B332F31332F323032362032333A363A303A3535383B5374617475733D31313030313B47656E636F6D703D31383B4465746C6F633D3332303B466C6167733D303B506172616D733D313B7B506172616D23303A4443317D3E"
},
"message": ""
}
Event ID 10029 — The activation of the CLSID param1 timed out waiting for the service param2 to stop.
Event ID 10030 — Unable to start a COM Server for debugging: param3.
Event ID 10031 — An unmarshaling policy check was performed when unmarshaling a custom marshaled object and the class param1 was rejected.
Event ID 10032 — An unmarshaling policy check was performed when unmarshaling a custom inproc handler and the class param1 was rejected.
Event ID 10033 — An unmarshaling policy check was performed when unmarshaling a COM+ envoy context property and the class param1 was rejected.
Event ID 10034 — An unmarshaling policy check was performed due to CLSCTX_NO_CUSTOM_MARSHAL and the class param1 was rejected.
Event ID 10035 — The COM standard marshaler was unable to fix a mismatch between the IID ProvidedIid provided by the server and the IID RequestedIid requested by the client, with hand...
Description
The COM standard marshaler was unable to fix a mismatch between the IID ProvidedIid provided by the server and the IID RequestedIid requested by the client, with handler CLSID HandlerClsid. The error code was HRESULT.
Message #
Fields #
| Name | Description |
|---|---|
ProvidedIid UnicodeString | — |
RequestedIid UnicodeString | — |
HandlerClsid UnicodeString | — |
HRESULT UnicodeString | — |
Event ID 10036 — The server-side authentication level policy does not allow the user DomainName\UserName SID (SID) from address ClientIPAddress to activate DCOM server.
Event ID 10037 — Application ApplicationName with PID PID is requesting to activate CLSID CLSID on computer ComputerName with explicitly set authentication level at ActivationAuthenticationLevel.
Event ID 10038 — Application ApplicationName with PID PID is requesting to activate CLSID CLSID on computer ComputerName with default activation authentication level at ActivationAuthenticationLevel.
Event ID 1073751850 — The COM sub system is suppressing duplicate event log entries for a duration of param1 seconds.
Description
The COM sub system is suppressing duplicate event log entries for a duration of seconds. The suppression timeout can be controlled by a REG_DWORD value named under the following registry key: HKLM\.
Message #
Fields #
| Name | Description |
|---|---|
param1 UnicodeString | — |
param2 UnicodeString | — |
param3 UnicodeString | — |