From 643ad3880e36681e4cb16ed83bc5236f2cb7dbeb Mon Sep 17 00:00:00 2001 From: swachchhanda000 Date: Fri, 21 Mar 2025 11:21:46 +0545 Subject: [PATCH] Added new COM Hijack related registries --- sysmonconfig-export-block.xml | 10 +++++++--- sysmonconfig-export.xml | 10 +++++++--- 2 files changed, 14 insertions(+), 6 deletions(-) diff --git a/sysmonconfig-export-block.xml b/sysmonconfig-export-block.xml index 00cf2ae..4e243bd 100644 --- a/sysmonconfig-export-block.xml +++ b/sysmonconfig-export-block.xml @@ -672,11 +672,15 @@ \Microsoft\Terminal Server Client\Servers\ \command\ - \ddeexec\ - {86C86720-42A0-1069-A2E8-08002B30309D} + \ddeexec\ + {86C86720-42A0-1069-A2E8-08002B30309D} exefile - \InprocServer32\(Default) + \InprocServer32\(Default) + \LocalServer32\(Default) + \TreatAs\(Default) + \ScriptletURL\(Default) + \Open\Command\DelegateExecute \Hidden \ShowSuperHidden diff --git a/sysmonconfig-export.xml b/sysmonconfig-export.xml index 056b417..4c97279 100644 --- a/sysmonconfig-export.xml +++ b/sysmonconfig-export.xml @@ -715,11 +715,15 @@ \Microsoft\Terminal Server Client\Servers\ \command\ - \ddeexec\ - {86C86720-42A0-1069-A2E8-08002B30309D} + \ddeexec\ + {86C86720-42A0-1069-A2E8-08002B30309D} exefile - \InprocServer32\(Default) + \InprocServer32\(Default) + \LocalServer32\(Default) + \TreatAs\(Default) + \ScriptletURL\(Default) + \Open\Command\DelegateExecute \Hidden \ShowSuperHidden