APT28 Prismex COM Hijack via HKCU InprocServer32 Registration
Detects modifications or creation of 'InprocServer32' registry keys within 'HKEY_CURRENT_USER\Software\Classes\CLSID'. This pattern is frequently used for COM hijacking to achieve persistence or execute arbitrary code when a COM object is invoked by an application or the OS.
Microsoft Sentinel (KQL)

