1200KM / detection
T1546.015 Component Object Model Hijacking — Detection Rules
Detection workspace for T1546.015 Component Object Model Hijacking: 8 Sigma sources, 0 Atlas concepts and 0 anomaly models. No live detection validation.
Source-backed rule directory
- Suspicious GetTypeFromCLSID ShellExecute · test · medium · {"product":"windows","category":"ps_script","definition":"Requirements: Script Block Logging must be enabled"}
- Rundll32 Registered COM Objects · test · high · {"category":"process_creation","product":"windows"}
- Potential Persistence Using DebugPath · test · medium · {"category":"registry_set","product":"windows"}
- COM Object Hijacking Via Modification Of Default System CLSID Default Value · experimental · high · {"category":"registry_set","product":"windows"}
- Potential COM Object Hijacking Via TreatAs Subkey - Registry · test · medium · {"category":"registry_set","product":"windows"}
- Potential PSFactoryBuffer COM Hijacking · test · high · {"category":"registry_set","product":"windows"}
- Potential Persistence Via Scrobj.dll COM Hijacking · test · medium · {"category":"registry_set","product":"windows"}
- COM Hijacking via TreatAs · test · medium · {"category":"registry_set","product":"windows"}
Atlas deterministic concepts
No exact concept selected.
Anomaly models
No exact Atlas model in this snapshot.
ATT&CK analytic guidance
DET0481 Windows COM Hijacking Detection via Registry and DLL Load Correlation
AN1323 Analytic 1323
Correlate suspicious registry modifications to known COM object CLSIDs with subsequent DLL loads or unexpected binary execution paths. Detect placement of COM CLSID entries under HKEY_CURRENT_USER\Software\Classes\CLSID\ overriding default HKLM paths. Flag anomalous DLL loads traced back to hijacked COM registry changes.
Connected ecosystem references
Linked tags
Simulation, tools and telemetry
Threat actor context
These are explicit actor-to-technique associations in the existing Threat Matrix snapshot, not attribution of an event or proof that a detector identifies the actor. No tool-to-actor relationship is inferred.
Existing anomaly research
Pinned research references. No browser attack runner, live simulation result or validated detector is asserted. Source mappings and validation limits are preserved. ATT&CK / Atomic provenance · Detection provenance.