COM Hijacking via Suspicious Path
Detects modifications to Windows Registry keys related to Component Object Model (COM) objects (CLSID or InprocServer32) where the registry value points to suspicious file paths, specifically those within temporary directories like Temp or AppData. This behavior is indicative of an attacker attempting to establish persistence or perform privilege escalation by hijacking COM object execution flow.
Microsoft Sentinel (KQL)

