{"id":"T1546.015","name":"Component Object Model Hijacking","url":"https://attack.mitre.org/techniques/T1546/015","tactics":["privilege-escalation","persistence"],"platforms":["Windows"],"live":true,"revoked":false,"deprecated":false,"revoked_by":null,"detection_strategies":[{"id":"DET0481","stix_id":"x-mitre-detection-strategy--78340b60-535e-4f2e-a376-c6fcc53a3c4a","name":"Windows COM Hijacking Detection via Registry and DLL Load Correlation","url":"https://attack.mitre.org/detectionstrategies/DET0481","analytics":[{"id":"AN1323","stix_id":"x-mitre-analytic--cda93955-7500-49dd-9150-94bedae91d22","name":"Analytic 1323","description":"Correlate suspicious registry modifications to known COM object CLSIDs with subsequent DLL loads or unexpected binary execution paths. Detect placement of COM CLSID entries under HKEY_CURRENT_USER\\Software\\Classes\\CLSID\\ overriding default HKLM paths. Flag anomalous DLL loads traced back to hijacked COM registry changes.","url":"https://attack.mitre.org/detectionstrategies/DET0481#AN1323","platforms":["Windows"],"log_source_references":[{"name":"WinEventLog:Security","channel":"EventCode=4657","data_component":"DC0063","data_component_name":"Windows Registry Key Modification","log_source_slug":"wineventlog-security"},{"name":"WinEventLog:Sysmon","channel":"EventCode=1","data_component":"DC0032","data_component_name":"Process Creation","log_source_slug":"wineventlog-sysmon"},{"name":"WinEventLog:Sysmon","channel":"EventCode=7","data_component":"DC0016","data_component_name":"Module Load","log_source_slug":"wineventlog-sysmon"}],"mutable_elements":[{"field":"RegistryPathScope","description":"Defenders may tune specific monitored CLSIDs depending on known-good application behavior."},{"field":"BinaryPathAnomalyThreshold","description":"May require tuning based on environment to distinguish rare-but-legit COM DLLs vs suspicious ones."},{"field":"TimeWindow","description":"Correlating registry changes to DLL load or process execution may require configurable time window."},{"field":"UserContextFilter","description":"Tuning detection by isolating activity to specific user SIDs or admin-level activity may reduce false positives."}],"live":true,"detection_strategies":["DET0481"],"techniques":["T1546.015"]}],"live":true,"version":"1.0","techniques":["T1546.015"]}],"sigma_rules":[{"id":"243380fa-11eb-4141-af92-e14925e77c1b","title":"Potential PSFactoryBuffer COM Hijacking","author":"BlackBerry Threat Research and Intelligence Team - @Joseliyo_Jstnk","status":"test","level":"high","date":"2023-06-07","modified":"2023-08-17","description":"Detects changes to the PSFactory COM InProcServer32 registry. This technique was used by RomCom to create persistence storing a malicious DLL.","references":["https://blogs.blackberry.com/en/2023/06/romcom-resurfaces-targeting-ukraine","https://strontic.github.io/xcyclopedia/library/clsid_C90250F3-4D7D-4991-9B69-A5C5BC1C2AE6.html","https://www.virustotal.com/gui/file/6d3ab9e729bb03ae8ae3fcd824474c5052a165de6cb4c27334969a542c7b261d/detection","https://www.trendmicro.com/en_us/research/23/e/void-rabisu-s-use-of-romcom-backdoor-shows-a-growing-shift-in-th.html"],"logsource":{"product":"windows","category":"registry_set"},"tags":["attack.privilege-escalation","attack.persistence","attack.t1546.015"],"path":"rules/windows/registry/registry_set/registry_set_persistence_comhijack_psfactorybuffer.yml","techniques":["T1546.015"],"cves":[]},{"id":"790317c0-0a36-4a6a-a105-6e576bf99a14","title":"COM Object Hijacking Via Modification Of Default System CLSID Default Value","author":"Nasreddine Bencherchali (Nextron Systems)","status":"experimental","level":"high","date":"2024-07-16","modified":"2025-11-10","description":"Detects potential COM object hijacking via modification of default system CLSID.","references":["https://www.microsoft.com/security/blog/2022/07/27/untangling-knotweed-european-private-sector-offensive-actor-using-0-day-exploits/ (idea)","https://unit42.paloaltonetworks.com/snipbot-romcom-malware-variant/","https://blog.talosintelligence.com/uat-5647-romcom/","https://global.ptsecurity.com/analytics/pt-esc-threat-intelligence/darkhotel-a-cluster-of-groups-united-by-common-techniques","https://threatbook.io/blog/Analysis-of-APT-C-60-Attack-on-South-Korea","https://catalyst.prodaft.com/public/report/inside-the-latest-espionage-campaign-of-nebulous-mantis","https://github.com/rtecCyberSec/BitlockMove","https://cert.gov.ua/article/6284080","https://securelist.com/forumtroll-apt-hacking-team-dante-spyware/117851/"],"logsource":{"product":"windows","category":"registry_set"},"tags":["attack.privilege-escalation","attack.persistence","attack.t1546.015"],"path":"rules/windows/registry/registry_set/registry_set_persistence_com_hijacking_builtin.yml","techniques":["T1546.015"],"cves":[]},{"id":"7ba08e95-1e0b-40cd-9db5-b980555e42fd","title":"SOURGUM Actor Behaviours","author":"MSTIC, FPT.EagleEye","status":"test","level":"high","date":"2021-06-15","modified":"2022-10-09","description":"Suspicious behaviours related to an actor tracked by Microsoft as SOURGUM","references":["https://www.virustotal.com/gui/file/c299063e3eae8ddc15839767e83b9808fd43418dc5a1af7e4f44b97ba53fbd3d/detection","https://github.com/Azure/Azure-Sentinel/blob/43e9be273dca321295190bfc4902858e009d4a35/Detections/MultipleDataSources/SOURGUM_IOC.yaml","https://www.microsoft.com/security/blog/2021/07/15/protecting-customers-from-a-private-sector-offensive-actor-using-0-day-exploits-and-devilstongue-malware/"],"logsource":{"product":"windows","category":"process_creation"},"tags":["attack.t1546","attack.t1546.015","attack.persistence","attack.privilege-escalation","detection.emerging-threats"],"path":"rules-emerging-threats/2021/TA/SOURGUM/proc_creation_win_apt_sourgrum.yml","techniques":["T1546","T1546.015"],"cves":[]},{"id":"8bc063d5-3a3a-4f01-a140-bc15e55e8437","title":"Suspicious GetTypeFromCLSID ShellExecute","author":"frack113","status":"test","level":"medium","date":"2022-04-02","modified":null,"description":"Detects suspicious Powershell code that execute COM Objects","references":["https://github.com/redcanaryco/atomic-red-team/blob/f339e7da7d05f6057fdfcdd3742bfcf365fee2a9/atomics/T1546.015/T1546.015.md#atomic-test-2---powershell-execute-com-object"],"logsource":{"product":"windows","category":"ps_script"},"tags":["attack.privilege-escalation","attack.persistence","attack.t1546.015"],"path":"rules/windows/powershell/powershell_script/posh_ps_susp_gettypefromclsid.yml","techniques":["T1546.015"],"cves":[]},{"id":"9b0f8a61-91b2-464f-aceb-0527e0a45020","title":"Potential COM Object Hijacking Via TreatAs Subkey - Registry","author":"Kutepov Anton, oscd.community","status":"test","level":"medium","date":"2019-10-23","modified":"2025-10-26","description":"Detects COM object hijacking via TreatAs subkey","references":["https://bohops.com/2018/08/18/abusing-the-com-registry-structure-part-2-loading-techniques-for-evasion-and-persistence/"],"logsource":{"product":"windows","category":"registry_set"},"tags":["attack.privilege-escalation","attack.persistence","attack.t1546.015"],"path":"rules/windows/registry/registry_set/registry_set_persistence_com_key_linking.yml","techniques":["T1546.015"],"cves":[]},{"id":"dc5c24af-6995-49b2-86eb-a9ff62199e82","title":"COM Hijacking via TreatAs","author":"frack113","status":"test","level":"medium","date":"2022-08-28","modified":"2025-07-11","description":"Detect modification of TreatAs key to enable \"rundll32.exe -sta\" command","references":["https://github.com/redcanaryco/atomic-red-team/blob/40b77d63808dd4f4eafb83949805636735a1fd15/atomics/T1546.015/T1546.015.md","https://www.youtube.com/watch?v=3gz1QmiMhss&t=1251s"],"logsource":{"product":"windows","category":"registry_set"},"tags":["attack.privilege-escalation","attack.persistence","attack.t1546.015"],"path":"rules/windows/registry/registry_set/registry_set_treatas_persistence.yml","techniques":["T1546.015"],"cves":[]},{"id":"df4dc653-1029-47ba-8231-3c44238cc0ae","title":"Potential Persistence Using DebugPath","author":"frack113","status":"test","level":"medium","date":"2022-07-27","modified":"2023-08-17","description":"Detects potential persistence using Appx DebugPath","references":["https://oddvar.moe/2018/09/06/persistence-using-universal-windows-platform-apps-appx/","https://github.com/rootm0s/WinPwnage"],"logsource":{"product":"windows","category":"registry_set"},"tags":["attack.privilege-escalation","attack.persistence","attack.t1546.015"],"path":"rules/windows/registry/registry_set/registry_set_persistence_appx_debugger.yml","techniques":["T1546.015"],"cves":[]},{"id":"f1edd233-30b5-4823-9e6a-c4171b24d316","title":"Rundll32 Registered COM Objects","author":"frack113","status":"test","level":"high","date":"2022-02-13","modified":"2023-02-09","description":"load malicious registered COM objects","references":["https://nasbench.medium.com/a-deep-dive-into-rundll32-exe-642344b41e90","https://github.com/redcanaryco/atomic-red-team/blob/f339e7da7d05f6057fdfcdd3742bfcf365fee2a9/atomics/T1546.015/T1546.015.md"],"logsource":{"product":"windows","category":"process_creation"},"tags":["attack.privilege-escalation","attack.persistence","attack.t1546.015"],"path":"rules/windows/process_creation/proc_creation_win_rundll32_registered_com_objects.yml","techniques":["T1546.015"],"cves":[]},{"id":"fe20dda1-6f37-4379-bbe0-a98d400cae90","title":"Potential Persistence Via Scrobj.dll COM Hijacking","author":"frack113","status":"test","level":"medium","date":"2022-08-20","modified":"2023-08-17","description":"Detect use of scrobj.dll as this DLL looks for the ScriptletURL key to get the location of the script to execute","references":["https://github.com/redcanaryco/atomic-red-team/blob/40b77d63808dd4f4eafb83949805636735a1fd15/atomics/T1546.015/T1546.015.md"],"logsource":{"product":"windows","category":"registry_set"},"tags":["attack.privilege-escalation","attack.persistence","attack.t1546.015"],"path":"rules/windows/registry/registry_set/registry_set_persistence_scrobj_dll.yml","techniques":["T1546.015"],"cves":[]}],"kev_cves":[],"_built":"2026-08-23 05:47 UTC","_attack_version":"19.2","_sigma_commit":"da9bb07d642a2826e89702445d32c795209ec108"}