1200KM / simulation
T1546.015 Component Object Model Hijacking — Attack Simulation
Adversaries may establish persistence by executing malicious content triggered by hijacked references to Component Object Model (COM) objects. COM is a system within Windows to enable interaction between software components through the operating system. References to various COM objects are stored in the Registry. Adversaries may use the COM system to insert malicious code that can be executed in place of legitimate software through hijacking…
Technique description
Adversaries may establish persistence by executing malicious content triggered by hijacked references to Component Object Model (COM) objects. COM is a system within Windows to enable interaction between software components through the operating system. References to various COM objects are stored in the Registry. Adversaries may use the COM system to insert malicious code that can be executed in place of legitimate software through hijacking…
At least one platform-compatible Atomic procedure is documented. Individual review, lab prerequisites, and validation remain required.
Official ATT&CK definition · Detection rules and anomaly models
Documented simulation candidates
- COM Hijacking with RunDLL32 (Local Server Switch)
Procedure 123520cc-e998-471b-a920-bd28e3feafa0; elevation not declared required; cleanup present, not reviewed. Not executed or individually validated.
- COM hijacking via TreatAs
Procedure 33eacead-f117-4863-8eb0-5c6304fbfaa9; elevation not declared required; cleanup present, not reviewed. Not executed or individually validated.
- COM Hijacking - InprocServer32
Procedure 48117158-d7be-441b-bc6a-d9e36e47b52b; elevation not declared required; cleanup present, not reviewed. Not executed or individually validated.
- Powershell Execute COM Object
Procedure 752191b1-7c71-445c-9dbe-21bb031b18eb; elevation not declared required; cleanup present, not reviewed. Not executed or individually validated.
Connected ecosystem references
Linked tags
Detection and collection
Attack tools
Threat actor context
These are explicit actor-to-technique associations in the existing Threat Matrix snapshot, not attribution of an event or proof that a detector identifies the actor. No tool-to-actor relationship is inferred.
Existing research
Pinned research references. No browser attack runner, live simulation result or validated detector is asserted. Source mappings and validation limits are preserved. ATT&CK / Atomic provenance · Detection provenance.