ION28 / BLUESPAWN

An Active Defense and EDR software to empower Blue Teams
GNU General Public License v3.0
1.24k stars 170 forks source link

Add Hunt for T1122 COM Hijack #269

Closed ION28 closed 4 years ago

ION28 commented 4 years ago

https://attack.mitre.org/techniques/T1122/

{USERS + HKLM} \Software\Classes\CLSID{82CA8DE3-01AD-4CEA-9D75-BE4C51810A9E}\InprocServer32 , LocalServer32

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellIconOverlayIdentifiers\ GoogleDriveSynced

(locations of CLSIDs)

ION28 commented 4 years ago

https://www.gdatasoftware.com/blog/2014/10/23941-com-object-hijacking-the-discreet-way-of-persistence