Techniques
Sample rules
Potential Persistence Via Scrobj.dll COM Hijacking
- source: sigma
- technicques:
- t1546
- t1546.015
Description
Detect use of scrobj.dll as this DLL looks for the ScriptletURL key to get the location of the script to execute
Detection logic
condition: selection
selection:
Details: C:\WINDOWS\system32\scrobj.dll
TargetObject|endswith: InprocServer32\(Default)