top of page
attacking and defending

Position COMpromised :
Weaponizing Windows COM for Stealth Execution

11 July 2026  |  10:00 AM ET  |  2+ Hours Duration

hacker summer  webinar page  banner final 1.png

Overview

The Component Object Model or COM is a framework built to provide interoperability between software components in a Windows environment. This allows components to interact with each other independently of the language they were written in. Many Windows components like WMI, Microsoft Office and other third party applications expose their functionalities through COM objects.

These COM objects may often expose functionalities which allow file creation, process creation and even command execution which makes COM a very interesting target for attackers.

This two-hour session begins with an introduction to COM, explaining its architecture and role within Windows, and why it matters from an offensive perspective. Attendees will explore how COM can be abused to achieve a variety of objectives, including code execution, persistence, privilege escalation, and evasion.

The session will showcase why COM continues to be attractive to attackers, highlight abuse opportunities, and discuss common techniques used during offensive operations.

The talk concludes with a high-level look at detection considerations, helping defenders better understand where malicious COM-related activity may show up within their environments. Finally, attendees will also be introduced to advanced areas of study and related Windows internals topics-to continue their learning beyond the session.

webinar 11 july 16x9.png

Register

Get the latest updates on exclusive offers, webinars, giveaways, and key activities delivered directly to your inbox.

Watch the Recorded Webinar

Attend Live Webinar

11 July 2026 | 10:00 AM ET | 2+ Hours Duration

Get Webinar Participation Certificate

HS-C-02-Position.jpg

MEET THE INSTRUCTOR

Manthan Chhabra

Manthan profile pic.jpeg

Manthan is a security researcher at Altered Security with a strong passion for enterprise security, red teaming and Active Directory security. He specializes in testing enterprise security defences with a deep understanding of offensive strategies, including EDR evasion and Active Directory attacks. He continuously researches emerging threats, attack techniques, and mitigation strategies to stay ahead of evolving adversaries.

bottom of page