COM Hijack via Sdclt

 Original Source: [Sigma source]
Title: COM Hijack via Sdclt
Status: test
Description:Detects changes to 'HKCU\Software\Classes\Folder\shell\open\command\DelegateExecute'
References:
  -http://blog.sevagas.com/?Yet-another-sdclt-UAC-bypass
  -https://www.exploit-db.com/exploits/47696
Author: Omkar Gudhate
Date: 2020-09-27
modified:2023-09-28
Tags:
  • -'attack.persistence'
  • -'attack.privilege-escalation'
  • -'attack.t1546'
  • -'attack.t1548'
Logsource:
  • category: registry_set
  • product: windows
Detection:
  selection:
    TargetObject|contains: '\Software\Classes\Folder\shell\open\command\DelegateExecute'
  condition:selection
Falsepositives:
  -Unknown
Level: high