Component Object Model (COM) Hijacking

This KQL detection is designed for use in Microsoft Defender for Endpoint Advanced Hunting or Microsoft Sentinel, depending on table availability. It focuses on identifying two common persistence techniques used by threat actors: COM hijacking via user-specific registry hives (InprocServer32 and LocalServer32), particularly when leveraged by .NET or PowerShell-based malware; and uncommon registry-based persistence through suspicious keys such as DelegateExecute, TreatAs, and ScriptletURL. The KQL focusses on user-specific registry hives as they don't require elevated privileges to modify and is why we also ignore "nt authority" activity as this detection is focused on low hanging fruit that would be easily accessible to a threat actor initially for persistence without privilege escalation.