A comprehensive, research-grade knowledge base on Windows COM offensive security, covering fundamentals, lateral movement, privilege escalation, UAC bypass, persistence, execution/defense evasion, detection engineering, and zero-day research methodology.

Stars

134

7-day growth

+6

Forks

20

Open issues

0

License

No data

Last updated

2026-07-20

AI repository intelligence
FR-AI / ANALYSIS

Why it is worth attention

It is a structured, all-in-one resource that takes a reader from COM basics to advanced zero-day hunting, featuring 28 diagrams, runnable lab snippets, per-technique detection guidance, and a repeatable research lab methodology at the end of each attack chapter.

Who it is for

  • Red teamers starting with little COM background
  • Security researchers hunting for COM zero-days
  • Penetration testers needing practical attack techniques
  • Detection engineers building COM telemetry and signatures

Use cases

  • Learning COM fundamentals for offensive security
  • Performing DCOM lateral movement or COM privilege escalation in authorized tests
  • Identifying and bypassing UAC via COM hijacking
  • Hunting for new COM vulnerabilities using the provided research pipeline

Strengths

  • Covers the full spectrum from COM basics to fuzzing marshaled NDR buffers against SYSTEM COM servers
  • Includes 28 high-resolution technical diagrams and a contact sheet for quick reference
  • Provides detection engineering guidance with Sysmon/Security/ETW telemetry primer and layered coverage matrix
  • Every attack chapter ends with a repeatable Research Lab section (hypothesis → enumeration → fuzzing → weaponization)

Considerations

  • Content is AI-generated (by Kimi K3 Swarms) and may contain inaccuracies, hallucinations, or outdated information; all technical details must be verified
  • Windows behavior changes between builds; CLSIDs and patch status must be re-validated on the specific target version
  • Requires hands-on lab validation; claims marked '(verify in lab)' are not double-confirmed by the underlying research sources

README quick start

Offensive COM (Component Object Model)

[!WARNING] ⚠️ AI-generated slop ahead. These notes were generated by Kimi K3 Swarms and may contain inaccuracies, hallucinations, or outdated information. Treat them as a starting point for research—not as an authoritative reference. Verify all technical details before relying on them.

A complete, research-grade knowledge base on Windows COM (Component Object Model) offensive security, built for red teamers who start with little or no COM background and want to end up able to hunt for zero-days on their own.

Every chapter goes from "what is a CLSID" to "here is how to fuzz marshaled NDR buffers against a SYSTEM COM server" — with exact CLSIDs, registry paths, API signatures, runnable lab snippets, 28 purpose-built technical diagrams, per-technique detection guidance, and a Research Lab at the end of every attack category that turns the chapter into a repeatable hunting methodology.

Legal: This material is for authorized security testing, research, and defense only. Every technique here is published defensive knowledge drawn from the public research record (Project Zero, vendor advisories, conference talks, vendor blogs). Running any of it against systems you do not own or lack written authorization to test is illegal in most jurisdictions. You are responsible for your own lab.

Provenance: All facts, CLSIDs, CVEs, code snippets, and URLs in these chapters come from six cross-verified research briefs (kept in research/). Anything the sources could not double-confirm is explicitly marked "(verify in lab)" or carries a confidence label. Nothing is invented.

Powered By 🤖 Kimi K3 Max Swarm


How to use this knowledge base

If you are new to COM (the "zero to hero" path): Read 01 cover to cover first. It defines every term, walks the registry layout, activation, marshaling, apartments, monikers, and the security model. Then read the attack chapters in order — each one re-explains what it needs before going deep.

If you are an operator preparing for an engagement: Jump straight to the attack chapter you need. Each technique follows a fixed template: mechanics → prerequisites table → proof of concept → OpSec & detection → mitigations. Check 07 (Detection Engineering) against your target's likely telemetry before choosing a technique.

**If you wa

Description

Research notes on Windows Component Object Model (COM) attack surface for offensive security and vulnerability research. Covers COM hijacking, elevation of privilege, DCOM lateral movement, and persistence primitives with exploitation steps. Notes were generated by Kimi K3 Swarm may contain inaccuracies.

Related repositories

Similar projects matched by category, topics, and programming language.

lopopolo
Featured
lopopolo GitHub avatar

harness-engineering

Harness Engineering is a methodology for improving coding agent outputs by carefully crafting the environment around them—providing curated context, tools, and executable constraints that encode an organization’s nonfunctional requirements and cumulative lessons.

AI & Machine LearningAI Agents
2,390
slvDev
Featured
slvDev GitHub avatar

esp32-ai

A 28.9 million parameter language model runs on an $8 ESP32-S3 microcontroller entirely on-device, generating simple stories at about 9.5 tokens per second.

AI & Machine LearningLarge Language Models
1,960
littledivy
Featured
littledivy GitHub avatar

mimic

mimic captures traffic from any iOS or web app and automatically generates a Python client library that lets you call the app's API like a regular library.

AI & Machine Learning
1,482