Windows Registry Deletion of Shell Open Command COM Hijacking Key Paths
Flags registry deletions of \shell\open\command paths that may indicate removal of COM hijacking execution entries.
- Product
- windows
- Category
- registry_delete
- Author
- Roberto Rodriguez (Cyb3rWard0g), OTR (Open Threat Research) (SigmaHQ), DRL 1.1
- Published
- 2020-05-02
- Updated
- 2026-07-30
ATT&CK techniques
Persistence → Defense EvasionRecon
Resource Dev
Initial Access
Execution
Persistence
Priv Esc
Defense Evasion
Cred Access
Discovery
Lateral Movement
Collection
C2
Exfiltration
Impact
What it detects
This rule identifies Windows registry key deletions targeting any entries that end with the path \shell\open\command, which are commonly used for COM-related execution behaviors. Attackers may remove these keys to disrupt persistence or remove traces after manipulating COM-linked shell command registrations. It relies on Windows registry deletion telemetry and filters out common legitimate deletion sources based on the deleting process image path.
Reporting behind it
- github.comhttps://github.com/OTRF/detection-hackathon-apt29/issues/7
- github.comhttps://github.com/OTRF/ThreatHunter-Playbook/blob/2d4257f630f4c9770f78d0c1df059f891ffc3fec/docs/evals/apt29/detections/3.C.1_22A46621-7A92-48C1-81BF-B3937EB4FDC3.md
- learn.microsoft.comhttps://learn.microsoft.com/en-us/windows/win32/shell/launch
- learn.microsoft.comhttps://learn.microsoft.com/en-us/windows/win32/api/shobjidl_core/nn-shobjidl_core-iexecutecommand
- learn.microsoft.comhttps://learn.microsoft.com/en-us/windows/win32/shell/shell-and-managed-code
- github.comhttps://github.com/SigmaHQ/sigma/blob/master/rules/windows/registry/registry_delete/registry_delete_removal_com_hijacking_registry_key.yml
Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.
title: Windows Registry Deletion of Shell Open Command COM Hijacking Key Paths
id: c3347724-75e6-4766-befc-5f32527f2991
status: test
description: This rule identifies Windows registry key deletions targeting any entries that end with the path \shell\open\command, which are commonly used for COM-related execution behaviors. Attackers may remove these keys to disrupt persistence or remove traces after manipulating COM-linked shell command registrations. It relies on Windows registry deletion telemetry and filters out common legitimate deletion sources based on the deleting process image path.
references:
- https://github.com/OTRF/detection-hackathon-apt29/issues/7
- https://github.com/OTRF/ThreatHunter-Playbook/blob/2d4257f630f4c9770f78d0c1df059f891ffc3fec/docs/evals/apt29/detections/3.C.1_22A46621-7A92-48C1-81BF-B3937EB4FDC3.md
- https://learn.microsoft.com/en-us/windows/win32/shell/launch
- https://learn.microsoft.com/en-us/windows/win32/api/shobjidl_core/nn-shobjidl_core-iexecutecommand
- https://learn.microsoft.com/en-us/windows/win32/shell/shell-and-managed-code
- https://github.com/SigmaHQ/sigma/blob/master/rules/windows/registry/registry_delete/registry_delete_removal_com_hijacking_registry_key.yml
author: Roberto Rodriguez (Cyb3rWard0g), OTR (Open Threat Research), Huntrule Team
date: 2020-05-02
modified: 2025-10-07
tags:
- attack.persistence
- attack.defense-impairment
- attack.t1112
logsource:
product: windows
category: registry_delete
detection:
selection:
TargetObject|endswith: \shell\open\command
filter_main_explorer:
Image|endswith: C:\Windows\explorer.exe
filter_main_svchost:
Image: C:\Windows\system32\svchost.exe
filter_main_msiexec:
Image:
- C:\Windows\System32\msiexec.exe
- C:\Windows\SysWOW64\msiexec.exe
filter_main_generic_prorams:
Image|startswith:
- C:\Program Files\
- C:\Program Files (x86)\
filter_main_openwith:
Image: C:\Windows\System32\OpenWith.exe
filter_optional_dropbox:
Image|endswith: \Dropbox.exe
TargetObject|contains: \Dropbox.
filter_optional_wireshark:
Image|endswith: \AppData\Local\Temp\Wireshark_uninstaller.exe
TargetObject|contains: \wireshark-capture-file\
filter_optional_peazip:
Image|contains: peazip
TargetObject|contains: \PeaZip.
filter_optional_everything:
Image|endswith: \Everything.exe
TargetObject|contains: \Everything.
filter_optional_uninstallers:
Image|startswith: C:\Windows\Installer\MSI
filter_optional_java:
Image|startswith: C:\Program Files (x86)\Java\
Image|endswith: \installer.exe
TargetObject|contains: \Classes\WOW6432Node\CLSID\{4299124F-F2C3-41b4-9C73-9236B2AD0E8F}
filter_optional_edgeupdate:
Image|contains: \Microsoft\EdgeUpdate\Install
filter_optional_avira:
Image:
- C:\Program Files (x86)\Avira\Antivirus\
- C:\Program Files\Avira\Antivirus\
TargetObject|endswith:
- \CLSID\{305CA226-D286-468e-B848-2B2E8E697B74}\Shell\Open\Command
- \AntiVir.Keyfile\shell\open\command
filter_optional_installer_temp:
- Image|contains|all:
- AppData\Local\Temp
- \setup.exe
- Image|contains|all:
- \Temp\is-
- \target.tmp
filter_optional_ninite:
Image|endswith: \ninite.exe
filter_optional_discord:
Image|endswith: \reg.exe
TargetObject|endswith: \Discord\shell\open\command
filter_optional_spotify:
Image|endswith: \Spotify.exe
TargetObject|endswith: \Spotify\shell\open\command
filter_optional_eclipse:
Image|endswith: C:\eclipse\eclipse.exe
TargetObject|contains: _Classes\eclipse+
filter_optional_teamviewer:
Image|contains|all:
- \Temp
- \TeamViewer
condition: selection and not 1 of filter_main_* and not 1 of filter_optional_*
falsepositives:
- Legitimate software (un)installations are known to cause false positives. Please add them as a filter when encountered
level: medium
license: DRL-1.1
related:
- id: 96f697b0-b499-4e5d-9908-a67bec11cdb6
type: derived