Windows Registry Persistence via hhctrl CLSID InprocServer32 Default Modification

Flags registry changes to the hhctrl COM CLSID InprocServer32 (Default) to load a custom binary instead of the system hhctrl.ocx.

FreeReviewedSigma · High · v1
Product
windows
Category
registry_set
Author
Nasreddine Bencherchali (Nextron Systems) (SigmaHQ), DRL 1.1
Published
2022-07-21
Updated
2026-07-30

What it detects

This rule identifies when the registry value under the hhctrl COM CLSID InprocServer32 (Default) is modified to point to a non-System32 binary. Attackers use this technique to persist by loading a custom COM server component when the system or applications instantiate the CLSID. It relies on Windows registry set telemetry for the specific TargetObject path and excludes the expected value pointing to C:\Windows\System32\hhctrl.ocx.

Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.