elastic-protections
high
eql
Suspicious Windows Component Object Model via DLLHOST
Identifies the instantiation of a registered COM object by classID via DllHost and by an unusual process such as Windows scripts interpreters, recently dropped unsigned executables and common signed proxy binaries like Rundll32. Adversaries may use the Windows Component Object Model (COM) for local code execution, evasion or persistence.