Revisiting COM Hijacking
ID: d7d69969-ada1-58b0-bd1e-4e2e747bf754
STIX ID: report--d7d69969-ada1-58b0-bd1e-4e2e747bf754
Feed Name: SpecterOps Blog
This post outlines a red-team technique leveraging Windows COM hijacking to establish stealthy persistence and achieve controlled code execution within commonly used applications, especially Chromium-based browsers (Edge/Chrome). It covers discovering viable CLSIDs via Procmon, creating a proxy DLL to maintain application stability while triggering a payload, and adding process checks to limit execution to target browsers for better stealth and potential access to browser data.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
