TypeLib COM Hijacking Attempt - Registry

Rule Info

Name
TypeLib COM Hijacking Attempt - Registry
Author
Swachchhanda Shrawan Poudel (Nextron Systems)
Description
Detects typelib registry modifications, potential TypeLib COM Hijacking attempts. Attackers may alter typelib registry entries to redirect COM objects to malicious local or remote files.
Date
2025-04-22 00:00:00
Modified
None
Id
e6a75bbc-88a7-4b41-a7b6-f491627ef427
Tags
attack.persistence attack.t1546.015
Type
Nextron Sigma feed only (private)

Rule History