Windows COM Hijack by Registry DelegateExecute Modification (HKCU Classes Folder\shell\open\command)

Flags HKCU DelegateExecute registry changes for COM hijack style persistence under the Folder shell open command.

FreeReviewedSigma · High · v1
Product
windows
Category
registry_set
Author
Omkar Gudhate (SigmaHQ), DRL 1.1
Published
2020-09-27
Updated
2026-07-30

ATT&CK techniques

Persistence → Defense Evasion
  1. Recon

  2. Resource Dev

  3. Initial Access

  4. Execution

  5. Cred Access

  6. Discovery

  7. Lateral Movement

  8. Collection

  9. C2

  10. Exfiltration

  11. Impact

What it detects

This rule identifies registry set activity that changes the COM hijack persistence path under HKCU\Software\Classes\Folder\shell\open\command\DelegateExecute. Attackers use DelegateExecute values to redirect how Windows components invoke commands, often supporting privilege escalation or bypassing intended execution flows. It relies on telemetry that records registry value writes and matches events whose TargetObject contains the specified DelegateExecute registry path.

Related detections9 linkedT1548 — drag to rearrange
Malicious Azure Elevate Access to User Access Administrator
Suspicious User Home Directory Modification via dscl Process Creation
Possible GTFOBins Shell Breakout via apt Command
AdminSDHolder Permissions Changed for Persistence (via security)
Malicious Update Orchestrator Service Reconfiguration for Privilege Escalation
Malicious macOS Credential Verification via dscl authonly
Malicious setcap Assigning cap_sys_admin for GameOverlay Privilege Escalation (via process_creation)
Suspicious Persistence via Shell Script Dropped in profile.d Directory (via file_event)
Suspicious AWS GetFederationToken Console Access by JavaGhost (via cloudtrail)
Windows COM Hijack by Registry DelegateExecute Modification (HKCU Classes Folder\shell\open\command)
Pivot detection · T1548 · 9 related

Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.