Threaticon
Toggle sidebar

You're viewing a limited, public preview. Log in for full access.

Log in User Guide
Log in Get started
Detection Strategies DET0481 — Windows COM Hijacking Detection via Registry and DLL Load Correlation
DET0481

Windows COM Hijacking Detection via Registry and DLL Load Correlation

1 analytic(s) · 1 technique(s) detected

Analytics

1
AN1323 Analytic 1323
Windows

Correlate suspicious registry modifications to known COM object CLSIDs with subsequent DLL loads or unexpected binary execution paths. Detect placement of COM CLSID entries under HKEY_CURRENT_USER\Software\Classes\CLSID\ overriding default HKLM paths. Flag anomalous DLL loads traced back to hijacked COM registry changes.

WinEventLog:Security EventCode=4657 WinEventLog:Sysmon EventCode=1 WinEventLog:Sysmon EventCode=7
[RegistryPathScope] Defenders may tune specific monitored CLSIDs depending on known-good application behavior.
[BinaryPathAnomalyThreshold] May require tuning based on environment to distinguish rare-but-legit COM DLLs vs suspicious ones.
[TimeWindow] Correlating registry changes to DLL load or process execution may require configurable time window.
[UserContextFilter] Tuning detection by isolating activity to specific user SIDs or admin-level activity may reduce false positives.

Detected Techniques

1

Details

MITRE ID
DET0481
STIX ID
x-mitre-detection-strategy--78340b60-535e-4f2e-a376-c6fcc53a3c4a
Analytics
1
Techniques Detected
1
By Tactic
Privilege Escalation
1
Leaving Threaticon

This link opens an external site that isn't part of the platform.