Clankerusecase
MITRE ATT&CK detection coverage
← Back to main site
Home/ MITRE Matrix/ Privilege Escalation/ T1546.015

T1546.015Component Object Model Hijacking

T1546.015 — Component Object Model Hijacking is a MITRE ATT&CK technique in the Privilege Escalation tactic. Clankerusecase tracks 4 detection use cases covering it and 1 threat-intel article citing it.

Privilege EscalationPersistence
View on the matrix → Filter Detection Library MITRE official spec ↗
4Use cases
1Articles
0Sub-techniques
2Tactics

Use cases covering this technique (4)

Powershell COM Hijacking InprocServer32 Modification ESCU actions · alerting P Powershell Execute COM Object ESCU actions · alerting P Windows COM Hijacking InprocServer32 Modification ESCU actions · alerting P [LLM] Sednit COM-hijacking persistence via HKCU CLSID InprocServer32 to user-writable DLL Bespoke install · alerting DSΣPDDCS

Articles citing this technique (1)