Removal of Potential COM Hijacking Registry Keys — Detection Rule

Detects any deletion of entries in ".*\shell\open\command" registry keys. These registry keys might have been used for COM hijacking activities by a threat actor or an attacker and the deletion could indicate steps to remove its tracks.

Read the full analysis on IntelFusions