You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
name: persist via ShellServiceObjectDelayLoad registry key
namespace: persistence/registry
authors:
- xpzhxhm@gmail.com
description: Match on files using ShellServiceObjectDelayLoad to persist. Windows Explorer uses this key to load COM objects at startup, allowing malicious DLLs to execute automatically.
scopes:
static: function
dynamic: span of calls
att&ck:
- Persistence::Event Triggered Execution::Component Object Model Hijacking [T1546.015]