Skip to content
← LibraryTechnique entry
W-COM-HIJACKPersistence

COM Hijack

Register a per-user HKCU\Software\Classes COM CLSID that shadows a regularly-invoked HKLM class — fires when the system loads it.

§ Where this technique fits

W-COM-HIJACK is catalogued under the Persistence tactic of the offensive-security kill-chain. It appears in 0 approved dossiers in the registry, typically.