Cross-source coverage

T1173 / ATT&CK

Dynamic Data Exchange

ATT&CK has retired this technique. Rules still tag it; the current id is T1559.002 Inter-Process Communication: Dynamic Data Exchange.

1 rule across 1 source.

Showing deprecated rules · back to the default

From MITRE ATT&CK 19.2

Windows Dynamic Data Exchange (DDE) is a client-server protocol for one-time and/or continuous inter-process communication (IPC) between applications. Once a link is established, applications can autonomously exchange transactions consisting of strings, warm data links (notifications when a data item changes), hot data links (duplications of changes to a data item), and requests for command execution.

Object Linking and Embedding (OLE), or the ability to link data between documents, was originally implemented through DDE. Despite being superseded by COM, DDE may be enabled in Windows 10 and most of Microsoft Office 2016 via Registry keys.

Adversaries may use DDE to execute arbitrary commands. Microsoft Office documents can be poisoned with DDE commands, directly or through embedded files, and used to deliver execution via phishing campaigns or hosted Web content, avoiding the use of Visual Basic for Applications (VBA) macros. DDE could also be leveraged by an adversary operating on a compromised machine who does not have direct access to command line execution.

Tactics
Execution
Platforms
Windows
Telemetry

chronicle/detection-rules

1 rule
Detection Severity Format
dynamic_data_exchange_spawning_commandline_or_powershell_detector_sysmon_behavior Undefined YARA-L

Detection rules belong to the projects that publish them and remain under their own licenses. This site indexes and links to them; it claims no rights in them.