COM Object Hijacking via HKCU\Software\Classes\CLSID InprocServer32/LocalServer32
This rule detects modifications to Windows Registry keys related to COM object handlers (InprocServer32/LocalServer32) within User registry hives. It specifically identifies when a COM object is registered to point to a file path residing in suspicious, user-writable directories (e.g., Temp, AppData, Downloads) or arbitrary user directories, which is a common indicator of COM hijacking for persistence or privilege escalation.
Microsoft Sentinel (KQL)

