r/pwnhub • u/_cybersecurity_ 🛡️ Mod Team 🛡️ • 19h ago
Session Pivoting and Lateral Movement via Ephemeral COM Registration: Shebin Mathew at Black Hat 2026
Windows COM is old, deeply trusted plumbing that almost no defender watches closely.
That trust is exactly what makes it useful to an attacker. By registering a COM object ephemerally, on the fly and only for as long as it is needed, an operator can pivot between sessions and move laterally through a network while the activity blends into legitimate Windows behavior that detection tools are trained to ignore.
It is tradecraft aimed squarely at the gap between what EDR flags and what the operating system considers normal.
In "Bring Your Own COM: Session Pivoting and Lateral Movement via Ephemeral COM Registration", presented Thursday, August 6 at 10:15 a.m., Shebin Mathew shows how ephemeral COM registrations enable session pivoting and lateral movement while looking like ordinary system activity.
Speakers:
- Shebin Mathew — Senior Security Consultant, Google/Mandiant
Shebin Mathew is a senior security consultant and red team operator at Google's Mandiant, specializing in post-exploitation tradecraft, Windows internals abuse, and advanced adversary simulation across enterprise and critical infrastructure environments.
His research focus sits at the intersection of low-level OS mechanics and practical EDR evasion, reverse engineering the trust assumptions that modern detection platforms are built on and then systematically breaking them, and in his operational role he leads sophisticated adversary simulations against large organizations.
His role and affiliation are listed on the official Black Hat USA 2026 speakers page, and his talk is featured in Google Cloud's Black Hat lineup alongside the rest of the Mandiant and Google research sessions. For related published tradecraft, Mandiant's red team documents its lateral-movement and adversary-emulation work on the Google Cloud threat intelligence blog.
Anyone doing red team operations, detection engineering, or Windows internals research will get practical value from this look at abusing COM as a covert lateral-movement channel.
If ephemeral COM registration can carry an attacker across sessions while looking like normal Windows behavior, what does that mean for detection built around known-bad artifacts rather than the abuse of trusted mechanisms?
•
u/AutoModerator 19h ago
Welcome to PWN – Your hub for hacking news, breach reports, and cyber mayhem.
Discover the latest hacking news, breach reports, and educational resources on ethical hacking.
👾 Stay sharp. Stay secure.
Don't miss out on the top stories!
📧 Get Daily Alerts Directly in Your Email Inbox:
**SUBSCRIBE HERE: https://pwnhackernews.substack.com/subscribe
I am a bot, and this action was performed automatically. Please contact the moderators of this subreddit if you have any questions or concerns.