[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$fRaVvniw6y-UELl5G2GwRBF5GX6Fr0Fd1332Trs5E4J4":3},{"id":4,"question":5,"answer":6,"answerHtml":7,"slug":8,"keywords":9,"article":10,"status":34,"aiModel":39,"aiConfidence":39,"updatedAt":51,"createdAt":51,"_status":50},1021,"What is the core principle behind userland registry hijacking?","The principle is key value synchronization: modifying the default value of a registry key under `HKCU:\\Software\\Classes\\` automatically updates the corresponding key under `HKCR:\\` (if it already exists). This works because editing `HKCU` only requires standard user permissions, while modifying `HKCR` directly needs administrator privileges. Thus, a standard user can hijack high-privilege system registry entries by writing to their `HKCU` counterparts. For more details, see the [original article](\u002Fnews\u002Fuserland-registry-hijacking).","\u003Cp>The principle is key value synchronization: modifying the default value of a registry key under `HKCU:\\Software\\Classes\\` automatically updates the corresponding key under `HKCR:\\` (if it already exists). This works because editing `HKCU` only requires standard user permissions, while modifying `HKCR` directly needs administrator privileges. Thus, a standard user can hijack high-privilege system registry entries by writing to their `HKCU` counterparts. For more details, see the [original article](\u002Fnews\u002Fuserland-registry-hijacking).\u003C\u002Fp>\u003Cp>\u003Ca href=\"\u002Fnews\u002Fuserland-registry-hijacking\">Read the related One Day Sec article\u003C\u002Fa>\u003C\u002Fp>","what-is-the-core-principle-behind-userland-registry-hijacking-1777480693576","userland registry hijacking, key value synchronization, HKCU, HKCR, permissions",{"id":11,"title":12,"slug":13,"description":14,"content":15,"contentHtml":30,"cover":31,"author":32,"views":19,"readingTime":33,"status":34,"publishedAt":35,"seo":36,"tags":41,"qaPairs":42,"meta":47,"updatedAt":48,"createdAt":49,"_status":50},250,"Userland registry hijacking","userland-registry-hijacking","Explore userland registry hijacking for persistence and BypassUAC. Learn to hijack scheduled tasks and modify HKCR keys via HKCU with standard user permissions.",{"root":16},{"type":17,"format":18,"indent":19,"version":20,"children":21,"direction":29},"root","",0,1,[22],{"type":23,"format":18,"indent":19,"version":20,"children":24,"direction":29},"paragraph",[25],{"mode":26,"text":27,"type":28,"style":18,"detail":19,"format":19,"version":20},"normal","\u003Chtml>\u003Chead>\u003C\u002Fhead>\u003Cbody>\u003Ch2>0x00 Introduction\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>While researching \"Use SCT to Bypass Application Whitelisting Protection,\" I once had an idea: during the execution of the regsvr32 command to register a COM component, corresponding key values for the COM component are simultaneously created under the registry path HKEY_CLASSES_ROOT\\CLSID\\, and the subkey InprocServer32 under the classid contains the absolute path to scrobj.dll. So, if the key value of the subkey InprocServer32 is modified, could it achieve hijacking of certain operations?\u003C\u002Fp>\u003Cp>However, modifying key values under HKCR\\CLSID\\ actually requires administrator privileges, so I didn't delve deeper into this idea. Recently, Matt Nelson's (@enigma0x3) blog gave me a new perspective: it only requires standard user permissions to hijack high-privilege system registry key values, which gave me a new understanding of userland registry hijacking.\u003C\u002Fp>\u003Ch2>0x01 Overview\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>This article will introduce the principles of userland registry hijacking, analyze specific applications in Userland Persistence and BypassUAC through examples, and demonstrate a method for finding BypassUAC using Process Monitor.\u003C\u002Fp>\u003Ch2>0x02 Principles of Userland Registry Hijacking\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Ch3>1. Key Value Synchronization\u003C\u002Fh3>\u003Cp>Modifying the data of the default name in key values under HKCU:\\Software\\Classes\\ can simultaneously modify the data of the corresponding key value's default name under HKCR:\\ (provided that this registry entry already exists under HKCR:\\)\u003C\u002Fp>\u003Cp>For example:\u003C\u002Fp>\u003Cp>Editing the default value of HKEY_CURRENT_USER\\Software\\Classes\\mscfile\\shell\\open\\command to c:\\test\\admin.exe\u003C\u002Fp>\u003Cp>As shown in the figure\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fuploads\u002Fdocx_image_1770014878050_0_54970cf897.jpeg\">\u003C\u002Fp>\u003Cp>\u003Cstrong>Note:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>By default, HKEY_CURRENT_USER\\Software\\Classes\\ does not contain mscfile\\shell\\open\\command; it needs to be created manually.\u003C\u002Fp>\u003Cp>Navigating to HKEY_CLASSES_ROOT\\mscfile\\shell\\open\\command, it is found that the default value has been automatically changed to c:\\test\\admin.exe.\u003C\u002Fp>\u003Cp>As shown in the figure.\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fuploads\u002Fdocx_image_1770014879031_1_32bc188e66.jpeg\">\u003C\u002Fp>\u003Cp>\u003Cstrong>Note:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>Creating a new key under HKCU:\\Software\\Classes\\CLSID that does not exist in HKCR:\\CLSID will not update the data in HKCR:\\CLSID.\u003C\u002Fp>\u003Cp>As shown in the figure.\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fuploads\u002Fdocx_image_1770014879638_2_7143f5b07b.jpeg\">\u003C\u002Fp>\u003Cp>Creating HKEY_CURRENT_USER\\Software\\Classes\\mscfile\\shell\\open\\command\\1 and setting the default value data to 1 will not create a subkey 1 under HKEY_CLASSES_ROOT\\mscfile\\shell\\open\\command.\u003C\u002Fp>\u003Ch3>2. Permissions\u003C\u002Fh3>\u003Cul>\u003Cli>Modifying keys under HKCU only requires standard user permissions.\u003C\u002Fli>\u003Cli>Modifying keys under HKCR requires administrator permissions.\u003C\u002Fli>\u003C\u002Ful>\u003Cp>In summary, editing keys under HKCU:\\Software\\Classes\\ with standard user permissions can synchronize modifications to the corresponding keys under HKCR, which require administrator permissions.\u003C\u002Fp>\u003Cp>Based on the principles introduced above, it can be specifically applied in two aspects: Userland Persistence and BypassUAC:\u003C\u002Fp>\u003Ch2>0x03 Userland Persistence With Scheduled Tasks\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>If the registry key corresponding to a system scheduled task is hijacked and the absolute path of the DLL to be launched is modified, then a backdoor can be achieved with only ordinary user permissions. The specific operations are as follows:\u003C\u002Fp>\u003Ch3>1. View the correspondence between scheduled tasks and the registry\u003C\u002Fh3>\u003Cp>There is a correspondence between scheduled tasks in the system and the key values under the registry HKCU:\\Software\\Classes\\CLSID\\. You can directly view this using the script shared by Matt Nelson@enigma0x3.\u003C\u002Fp>\u003Cp>\u003Cstrong>Download address:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>https:\u002F\u002Fgithub.com\u002Fenigma0x3\u002FMisc-PowerShell-Stuff\u002Fblob\u002Fmaster\u002FGet-ScheduledTaskComHandler.ps1\u003C\u002Fp>\u003Cp>\u003Cstrong>Note:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>The information viewed through the scheduled task panel is incomplete. The scheduled task panel can be opened by: right-clicking on My Computer -&gt; Manage, then finding Scheduled Tasks, as shown in the figure.\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fuploads\u002Fdocx_image_1770014880349_3_ddbc06bab8.jpeg\">\u003C\u002Fp>\u003Cp>Some correspondences obtained by the PowerShell script are shown in the figure.\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fuploads\u002Fdocx_image_1770014881348_4_0970da0ba9.jpeg\">\u003C\u002Fp>\u003Cp>You can obtain the location of the registry key corresponding to each scheduled task and the DLL to be launched.\u003C\u002Fp>\u003Ch3>2. Modify the DLL location in the corresponding key value\u003C\u002Fh3>\u003Cp>After establishing the correspondence, it is necessary to locate the specific registry key location, namely HKEY_CURRENT_USER\\Software\\Classes\\CLSID\\{CLSID}. Typically, this key does not exist under HKCU and must be manually created. Set its default value to the absolute path of the test DLL that needs to be executed. Once the key is created, the corresponding key under HKCR will be updated synchronously, and the DLL launched by the scheduled task will consequently be modified.\u003C\u002Fp>\u003Cp>\u003Cstrong>Example:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>1. Examine the correspondence between the scheduled task and the registry\u003C\u002Fp>\u003Cp>Run Get-ScheduledTaskComHandler to find DLLs that can be hijacked. Select a common scheduled task—UserTask—with details as follows:\u003C\u002Fp>\u003Cp>TaskName      : UserTask\u003C\u002Fp>\u003Cp>CLSID         : {58fb76b9-ac85-4e55-ac04-427593b1d060}\u003C\u002Fp>\u003Cp>Dll           : C:\\Windows\\system32\\dimsjob.dll\u003C\u002Fp>\u003Cp>Logon         : True\u003C\u002Fp>\u003Cp>IsUserContext : True\u003C\u002Fp>\u003Cp>\u003Cstrong>Note:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>This operation requires querying keys under HKCR, so administrator privileges are necessary to obtain them.\u003C\u002Fp>\u003Cp>2. Modify the DLL location in the corresponding key\u003C\u002Fp>\u003Cp>Under HKEY_CURRENT_USER\\Software\\Classes\\CLSID\\, create a new key named {58fb76b9-ac85-4e55-ac04-427593b1d060}.\u003C\u002Fp>\u003Cp>Then create a new key named InprocServer32.\u003C\u002Fp>\u003Cp>Set its value to c:\\test\\MessageBox32.dll\u003C\u002Fp>\u003Cp>\u003Cstrong>Note:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>The registry key {58fb76b9-ac85-4e55-ac04-427593b1d060} is universal, with the same key value name across different systems\u003C\u002Fp>\u003Cp>The download address for MessageBox32.dll is:\u003C\u002Fp>\u003Cp>https:\u002F\u002Fgithub.com\u002Fenigma0x3\u002FMessageBox\u003C\u002Fp>\u003Cp>Actual testing found that the dll from https:\u002F\u002Fgithub.com\u002Fenigma0x3\u002FMessageBox\u002Ftree\u002Fmaster\u002Fbin fails on Win7; recompiling the source code to generate a new dll works\u003C\u002Fp>\u003Cp>At this point, check HKEY_CLASSES_ROOT\\CLSID\\{58fb76b9-ac85-4e55-ac04-427593b1d060}\\InprocServer32, the default value is modified to c:\\test\\MessageBox32.dll, as shown in the figure\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fuploads\u002Fdocx_image_1770014882161_5_d30e621ff7.jpeg\">\u003C\u002Fp>\u003Cp>After logging off the user and logging back in, MessageBox32.dll is loaded and a dialog box pops up\u003C\u002Fp>\u003Cp>However, an error in the DLL (0x800401F9) is reported in the Scheduled Task panel log, as shown in the figure\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fuploads\u002Fdocx_image_1770014883028_6_31643d1f41.jpeg\">\u003C\u002Fp>\u003Cp>It is suspected that the issue with export functions causes the DLL loading error. Use dumpbin to view the export functions of the original DLL corresponding to the UserTask scheduled task, execute:\u003C\u002Fp>\u003Cp>dumpbin \u002Fexports C:\\Windows\\system32\\dimsjob.dll\u003C\u002Fp>\u003Cp>\u003Cstrong>Note:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>The absolute path of the original DLL corresponding to UserTask is C:\\Windows\\system32\\dimsjob.dll\u003C\u002Fp>\u003Cp>Obtain the export function table of dimsjob.dll, as shown in the figure\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fuploads\u002Fdocx_image_1770014883811_7_1121a7cf23.jpeg\">\u003C\u002Fp>\u003Cp>Therefore, it is necessary to add new export functions to the DLL:\u003C\u002Fp>\u003Cul>\u003Cli>DllCanUnloadNow\u003C\u002Fli>\u003Cli>DllGetClassObject\u003C\u002Fli>\u003Cli>DllRegisterServer\u003C\u002Fli>\u003Cli>DllUnregisterServer\u003C\u002Fli>\u003C\u002Ful>\u003Cp>\u003Cstrong>Note:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>The specific method for adding export functions to the DLL is detailed in 'Code Execution of Regsvr32.exe' and is omitted here\u003C\u002Fp>\u003Cp>After successful addition, use dumpbin to view the results as shown in the figure\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fuploads\u002Fdocx_image_1770014884793_8_de12a6b44e.jpeg\">\u003C\u002Fp>\u003Cp>Replace the old MessageBox32.dll, log off the user, log back in, the new MessageBox32.dll is loaded, and a pop-up appears\u003C\u002Fp>\u003Cp>Check the logs in the Scheduled Task panel, the issue is resolved, and the operation is successfully completed, as shown in the figure\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fuploads\u002Fdocx_image_1770014885358_9_723e5814c2.jpeg\">\u003C\u002Fp>\u003Cp>The above operations can be automated via PowerShell. Modify the UserTask code as follows:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>function Invoke-ScheduledTaskComHandlerUserTask\u003Cbr>{\u003Cbr>    [CmdletBinding(SupportsShouldProcess = $True, ConfirmImpact = 'Medium')]\u003Cbr>    Param (\u003Cbr>        [Parameter(Mandatory = $True)]\u003Cbr>        [ValidateNotNullOrEmpty()]\u003Cbr>        [String]\u003Cbr>        $Command,\u003Cbr>\u003Cbr>        [Switch]\u003Cbr>        $Force\u003Cbr>    )\u003Cbr>    $ScheduledTaskCommandPath = \"HKCU:\\Software\\Classes\\CLSID\\{58fb76b9-ac85-4e55-ac04-427593b1d060}\\InprocServer32\"\u003Cbr>    if ($Force -or ((Get-ItemProperty -Path $ScheduledTaskCommandPath -Name '(default)' -ErrorAction SilentlyContinue) -eq $null)){\u003Cbr>        New-Item $ScheduledTaskCommandPath -Force |\u003Cbr>            New-ItemProperty -Name '(Default)' -Value $Command -PropertyType string -Force | Out-Null\u003Cbr>    }else{\u003Cbr>        Write-Verbose \"Key already exists, consider using -Force\"\u003Cbr>        exit\u003Cbr>    }\u003Cbr>\u003Cbr>    if (Test-Path $ScheduledTaskCommandPath) {\u003Cbr>        Write-Verbose \"Created registry entries to hijack the UserTask\"\u003Cbr>    }else{\u003Cbr>        Write-Warning \"Failed to create registry key, exiting\"\u003Cbr>        exit\u003Cbr>    }  \u003Cbr>}\u003Cbr>Invoke-ScheduledTaskComHandlerUserTask -Command \"C:\\test\\testmsg.dll\" -Verbose\u003Cbr>\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>Test system: Win7 x86\u003C\u002Fp>\u003Cp>After execution, when the user logs back in, the DLL is loaded, actual demonstration as shown in the figure\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fuploads\u002Fdocx_image_1770014886020_10_d43b8a3f7a.png\">\u003C\u002Fp>\u003Cp>Execute DLL_PROCESS_ATTACH() and DllGetClassObject() sequentially. Since DllGetClassObject() only displays a pop-up, taskhost.exe will show an error afterwards\u003C\u002Fp>\u003Cp>\u003Cstrong>Note:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>This is only a demonstration; specific solutions are not introduced here.\u003C\u002Fp>\u003Cp>At this point, the UserTask scheduled task has been successfully hijacked to load testmsg.dll at system startup.\u003C\u002Fp>\u003Ch2>0x04 UACBypass\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>Scheduled tasks have corresponding relationships with key values under HKCR:\\ in the registry. Similarly, some high-privilege programs also call key values under HKCR:\\, which creates the possibility for Bypass UAC.\u003C\u002Fp>\u003Cp>Using the same principle, by modifying key values under HKEY_CURRENT_USER\\Software\\Classes\\, the key values under HKCR:\\ are synchronously modified. If a high-privilege program calls the modified key values during its execution, Bypass UAC is naturally achieved, launching our specified program with high privileges.\u003C\u002Fp>\u003Cp>The challenge here lies in finding this high-privilege program.\u003C\u002Fp>\u003Cp>\u003Cstrong>Method:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>With the help of Process Monitor, you can view the registry, file, network, and inter-process call relationships during program execution.\u003C\u002Fp>\u003Cp>Next, use Process Monitor to reproduce the process discovered by Matt Nelson@enigma0x3.\u003C\u002Fp>\u003Ch3>1. Find a high-privilege exe\u003C\u002Fh3>\u003Cp>Matt Nelson@enigma0x3's method involves using sigcheck to view the exe's manifest.\u003C\u002Fp>\u003Cp>Parameters are as follows:\u003C\u002Fp>\u003Cp>sigcheck.exe -m c:\\windows\\system32\\eventvwr.exe\u003C\u002Fp>\u003Cp>The result is shown in the figure\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fuploads\u002Fdocx_image_1770014887208_11_8fca7a5c7a.jpeg\">\u003C\u002Fp>\u003Cp>From level=\"highestAvailable\", it is known that eventvwr.exe has high privileges\u003C\u002Fp>\u003Cp>\u003Cstrong>Note:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>A more intuitive method for judgment is provided:\u003C\u002Fp>\u003Cp>Check the file icon; if it has the UAC logo, it must be a high-privilege program, as shown in the figure\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fuploads\u002Fdocx_image_1770014887810_12_ce380588d0.jpeg\">\u003C\u002Fp>\u003Ch3>2. Use Process Monitor to view process call relationships\u003C\u002Fh3>\u003Cp>Start Process Monitor\u003C\u002Fp>\u003Cp>Run eventvwr.exe\u003C\u002Fp>\u003Cp>In Process Monitor, select Tools-Process Tree, find eventvwr.exe, right-click-Go To Event, as shown in the figure\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fuploads\u002Fdocx_image_1770014888517_13_125c03bb9c.jpeg\">\u003C\u002Fp>\u003Cp>Carefully examine the process call relationships, as shown in the figure\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fuploads\u002Fdocx_image_1770014889390_14_449d14e736.jpeg\">\u003C\u002Fp>\u003Cp>Find the following information:\u003C\u002Fp>\u003Cul>\u003Cli>eventvwr.exe has high privileges\u003C\u002Fli>\u003Cli>eventvwr.exe first queries the key HKCU\\Software\\Classes\\mscfile\\shell\\open\\command, and the result is NAME NOT FOUND\u003C\u002Fli>\u003Cli>eventvwr.exe then queries the key HKCR\\mscfile\\shell\\open\\command, and the result is SUCCESS\u003C\u002Fli>\u003C\u002Ful>\u003Ch3>3. Modification Test\u003C\u002Fh3>\u003Cp>What happens if we modify the key HKCU\\Software\\Classes\\mscfile\\shell\\open\\command so that the query result is SUCCESS?\u003C\u002Fp>\u003Cp>First, modify the key HKCU\\Software\\Classes\\mscfile\\shell\\open\\command to have the value calc.exe\u003C\u002Fp>\u003Cp>Run eventvwr.exe again and observe that calc.exe is launched\u003C\u002Fp>\u003Cp>Use Process Monitor to view the process invocation relationship, as shown in the figure\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fuploads\u002Fdocx_image_1770014890594_15_605e4bc47d.jpeg\">\u003C\u002Fp>\u003Cp>At this point, the query result for the key HKCU\\Software\\Classes\\mscfile\\shell\\open\\command is SUCCESS\u003C\u002Fp>\u003Cp>Thus, by modifying HKCU\\Software\\Classes\\mscfile\\shell\\open\\command, BypassUAC is successfully achieved, obtaining high privileges\u003C\u002Fp>\u003Cp>calc.exe has high privileges, as shown in the figure\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fuploads\u002Fdocx_image_1770014890951_16_e728218faa.jpeg\">\u003C\u002Fp>\u003Ch3>4. Additional Conclusions\u003C\u002Fh3>\u003Cp>After modifying HKCU\\Software\\Classes\\mscfile\\shell\\open\\command, the execution of all .msc files will be hijacked, such as gpedit.msc, as shown in the figure\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fuploads\u002Fdocx_image_1770014891201_17_215d4d5ebd.jpeg\">\u003C\u002Fp>\u003Cp>Following this method, I tested all high-privilege executables under system32 and have not yet discovered a UAC bypass using the same approach via the command key value, but other key values are still worth testing.\u003C\u002Fp>\u003Ch2>0x05 Defense\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>Windows 10 has patched this vulnerability, while older versions of Windows remain unpatched. Recommended defenses include:\u003C\u002Fp>\u003Cul>\u003Cli>set the UAC level to “Always Notify”\u003C\u002Fli>\u003Cli>remove the current user from the Local Administrators group\u003C\u002Fli>\u003Cli>alert on new registry entries in HKCU\\Software\\Classes\\\u003C\u002Fli>\u003C\u002Ful>\u003Cp>Quoted from https:\u002F\u002Fenigma0x3.net\u002F2016\u002F08\u002F15\u002Ffileless-uac-bypass-using-eventvwr-exe-and-registry-hijacking\u002F\u003C\u002Fp>\u003Ch2>0x06 Summary\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>There are many DLLs in scheduled tasks that can be used for persistence; monitoring these is recommended for defense.\u003C\u002Fp>\u003Cp>Using Process Monitor to find UAC bypass methods is worth further research, and new discoveries are certain to emerge.\u003C\u002Fp>\u003Cp>\u003Cstrong>Related learning materials:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>https:\u002F\u002Fenigma0x3.net\u002F2016\u002F08\u002F15\u002Ffileless-uac-bypass-using-eventvwr-exe-and-registry-hijacking\u002F\u003C\u002Fp>\u003Cp>https:\u002F\u002Fenigma0x3.net\u002F2016\u002F05\u002F25\u002Fuserland-persistence-with-scheduled-tasks-and-com-handler-hijacking\u002F\u003C\u002Fp>\u003Cp>https:\u002F\u002Fblog.gdatasoftware.com\u002F2014\u002F10\u002F23941-com-object-hijacking-the-discreet-way-of-persistence\u003C\u002Fp>\u003C\u002Fbody>\u003C\u002Fhtml>","text","ltr","\u003Chtml>\u003Chead>\u003C\u002Fhead>\u003Cbody>\u003Ch2>0x00 Introduction\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>While researching \"Use SCT to Bypass Application Whitelisting Protection,\" I once had an idea: during the execution of the regsvr32 command to register a COM component, corresponding key values for the COM component are simultaneously created under the registry path HKEY_CLASSES_ROOT\\CLSID\\, and the subkey InprocServer32 under the classid contains the absolute path to scrobj.dll. So, if the key value of the subkey InprocServer32 is modified, could it achieve hijacking of certain operations?\u003C\u002Fp>\u003Cp>However, modifying key values under HKCR\\CLSID\\ actually requires administrator privileges, so I didn't delve deeper into this idea. Recently, Matt Nelson's (@enigma0x3) blog gave me a new perspective: it only requires standard user permissions to hijack high-privilege system registry key values, which gave me a new understanding of userland registry hijacking.\u003C\u002Fp>\u003Ch2>0x01 Overview\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>This article will introduce the principles of userland registry hijacking, analyze specific applications in Userland Persistence and BypassUAC through examples, and demonstrate a method for finding BypassUAC using Process Monitor.\u003C\u002Fp>\u003Ch2>0x02 Principles of Userland Registry Hijacking\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Ch3>1. Key Value Synchronization\u003C\u002Fh3>\u003Cp>Modifying the data of the default name in key values under HKCU:\\Software\\Classes\\ can simultaneously modify the data of the corresponding key value's default name under HKCR:\\ (provided that this registry entry already exists under HKCR:\\)\u003C\u002Fp>\u003Cp>For example:\u003C\u002Fp>\u003Cp>Editing the default value of HKEY_CURRENT_USER\\Software\\Classes\\mscfile\\shell\\open\\command to c:\\test\\admin.exe\u003C\u002Fp>\u003Cp>As shown in the figure\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fapi\u002Fmedia\u002Ffile\u002Fdocx_image_1770014878050_0_54970cf897-1.jpeg\">\u003C\u002Fp>\u003Cp>\u003Cstrong>Note:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>By default, HKEY_CURRENT_USER\\Software\\Classes\\ does not contain mscfile\\shell\\open\\command; it needs to be created manually.\u003C\u002Fp>\u003Cp>Navigating to HKEY_CLASSES_ROOT\\mscfile\\shell\\open\\command, it is found that the default value has been automatically changed to c:\\test\\admin.exe.\u003C\u002Fp>\u003Cp>As shown in the figure.\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fapi\u002Fmedia\u002Ffile\u002Fdocx_image_1770014879031_1_32bc188e66-1.jpeg\">\u003C\u002Fp>\u003Cp>\u003Cstrong>Note:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>Creating a new key under HKCU:\\Software\\Classes\\CLSID that does not exist in HKCR:\\CLSID will not update the data in HKCR:\\CLSID.\u003C\u002Fp>\u003Cp>As shown in the figure.\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fapi\u002Fmedia\u002Ffile\u002Fdocx_image_1770014879638_2_7143f5b07b-1.jpeg\">\u003C\u002Fp>\u003Cp>Creating HKEY_CURRENT_USER\\Software\\Classes\\mscfile\\shell\\open\\command\\1 and setting the default value data to 1 will not create a subkey 1 under HKEY_CLASSES_ROOT\\mscfile\\shell\\open\\command.\u003C\u002Fp>\u003Ch3>2. Permissions\u003C\u002Fh3>\u003Cul>\u003Cli>Modifying keys under HKCU only requires standard user permissions.\u003C\u002Fli>\u003Cli>Modifying keys under HKCR requires administrator permissions.\u003C\u002Fli>\u003C\u002Ful>\u003Cp>In summary, editing keys under HKCU:\\Software\\Classes\\ with standard user permissions can synchronize modifications to the corresponding keys under HKCR, which require administrator permissions.\u003C\u002Fp>\u003Cp>Based on the principles introduced above, it can be specifically applied in two aspects: Userland Persistence and BypassUAC:\u003C\u002Fp>\u003Ch2>0x03 Userland Persistence With Scheduled Tasks\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>If the registry key corresponding to a system scheduled task is hijacked and the absolute path of the DLL to be launched is modified, then a backdoor can be achieved with only ordinary user permissions. The specific operations are as follows:\u003C\u002Fp>\u003Ch3>1. View the correspondence between scheduled tasks and the registry\u003C\u002Fh3>\u003Cp>There is a correspondence between scheduled tasks in the system and the key values under the registry HKCU:\\Software\\Classes\\CLSID\\. You can directly view this using the script shared by Matt Nelson@enigma0x3.\u003C\u002Fp>\u003Cp>\u003Cstrong>Download address:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>https:\u002F\u002Fgithub.com\u002Fenigma0x3\u002FMisc-PowerShell-Stuff\u002Fblob\u002Fmaster\u002FGet-ScheduledTaskComHandler.ps1\u003C\u002Fp>\u003Cp>\u003Cstrong>Note:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>The information viewed through the scheduled task panel is incomplete. The scheduled task panel can be opened by: right-clicking on My Computer -&gt; Manage, then finding Scheduled Tasks, as shown in the figure.\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fapi\u002Fmedia\u002Ffile\u002Fdocx_image_1770014880349_3_ddbc06bab8-1.jpeg\">\u003C\u002Fp>\u003Cp>Some correspondences obtained by the PowerShell script are shown in the figure.\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fapi\u002Fmedia\u002Ffile\u002Fdocx_image_1770014881348_4_0970da0ba9-1.jpeg\">\u003C\u002Fp>\u003Cp>You can obtain the location of the registry key corresponding to each scheduled task and the DLL to be launched.\u003C\u002Fp>\u003Ch3>2. Modify the DLL location in the corresponding key value\u003C\u002Fh3>\u003Cp>After establishing the correspondence, it is necessary to locate the specific registry key location, namely HKEY_CURRENT_USER\\Software\\Classes\\CLSID\\{CLSID}. Typically, this key does not exist under HKCU and must be manually created. Set its default value to the absolute path of the test DLL that needs to be executed. Once the key is created, the corresponding key under HKCR will be updated synchronously, and the DLL launched by the scheduled task will consequently be modified.\u003C\u002Fp>\u003Cp>\u003Cstrong>Example:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>1. Examine the correspondence between the scheduled task and the registry\u003C\u002Fp>\u003Cp>Run Get-ScheduledTaskComHandler to find DLLs that can be hijacked. Select a common scheduled task—UserTask—with details as follows:\u003C\u002Fp>\u003Cp>TaskName      : UserTask\u003C\u002Fp>\u003Cp>CLSID         : {58fb76b9-ac85-4e55-ac04-427593b1d060}\u003C\u002Fp>\u003Cp>Dll           : C:\\Windows\\system32\\dimsjob.dll\u003C\u002Fp>\u003Cp>Logon         : True\u003C\u002Fp>\u003Cp>IsUserContext : True\u003C\u002Fp>\u003Cp>\u003Cstrong>Note:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>This operation requires querying keys under HKCR, so administrator privileges are necessary to obtain them.\u003C\u002Fp>\u003Cp>2. Modify the DLL location in the corresponding key\u003C\u002Fp>\u003Cp>Under HKEY_CURRENT_USER\\Software\\Classes\\CLSID\\, create a new key named {58fb76b9-ac85-4e55-ac04-427593b1d060}.\u003C\u002Fp>\u003Cp>Then create a new key named InprocServer32.\u003C\u002Fp>\u003Cp>Set its value to c:\\test\\MessageBox32.dll\u003C\u002Fp>\u003Cp>\u003Cstrong>Note:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>The registry key {58fb76b9-ac85-4e55-ac04-427593b1d060} is universal, with the same key value name across different systems\u003C\u002Fp>\u003Cp>The download address for MessageBox32.dll is:\u003C\u002Fp>\u003Cp>https:\u002F\u002Fgithub.com\u002Fenigma0x3\u002FMessageBox\u003C\u002Fp>\u003Cp>Actual testing found that the dll from https:\u002F\u002Fgithub.com\u002Fenigma0x3\u002FMessageBox\u002Ftree\u002Fmaster\u002Fbin fails on Win7; recompiling the source code to generate a new dll works\u003C\u002Fp>\u003Cp>At this point, check HKEY_CLASSES_ROOT\\CLSID\\{58fb76b9-ac85-4e55-ac04-427593b1d060}\\InprocServer32, the default value is modified to c:\\test\\MessageBox32.dll, as shown in the figure\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fapi\u002Fmedia\u002Ffile\u002Fdocx_image_1770014882161_5_d30e621ff7-1.jpeg\">\u003C\u002Fp>\u003Cp>After logging off the user and logging back in, MessageBox32.dll is loaded and a dialog box pops up\u003C\u002Fp>\u003Cp>However, an error in the DLL (0x800401F9) is reported in the Scheduled Task panel log, as shown in the figure\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fapi\u002Fmedia\u002Ffile\u002Fdocx_image_1770014883028_6_31643d1f41-1.jpeg\">\u003C\u002Fp>\u003Cp>It is suspected that the issue with export functions causes the DLL loading error. Use dumpbin to view the export functions of the original DLL corresponding to the UserTask scheduled task, execute:\u003C\u002Fp>\u003Cp>dumpbin \u002Fexports C:\\Windows\\system32\\dimsjob.dll\u003C\u002Fp>\u003Cp>\u003Cstrong>Note:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>The absolute path of the original DLL corresponding to UserTask is C:\\Windows\\system32\\dimsjob.dll\u003C\u002Fp>\u003Cp>Obtain the export function table of dimsjob.dll, as shown in the figure\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fapi\u002Fmedia\u002Ffile\u002Fdocx_image_1770014883811_7_1121a7cf23-1.jpeg\">\u003C\u002Fp>\u003Cp>Therefore, it is necessary to add new export functions to the DLL:\u003C\u002Fp>\u003Cul>\u003Cli>DllCanUnloadNow\u003C\u002Fli>\u003Cli>DllGetClassObject\u003C\u002Fli>\u003Cli>DllRegisterServer\u003C\u002Fli>\u003Cli>DllUnregisterServer\u003C\u002Fli>\u003C\u002Ful>\u003Cp>\u003Cstrong>Note:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>The specific method for adding export functions to the DLL is detailed in 'Code Execution of Regsvr32.exe' and is omitted here\u003C\u002Fp>\u003Cp>After successful addition, use dumpbin to view the results as shown in the figure\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fapi\u002Fmedia\u002Ffile\u002Fdocx_image_1770014884793_8_de12a6b44e-1.jpeg\">\u003C\u002Fp>\u003Cp>Replace the old MessageBox32.dll, log off the user, log back in, the new MessageBox32.dll is loaded, and a pop-up appears\u003C\u002Fp>\u003Cp>Check the logs in the Scheduled Task panel, the issue is resolved, and the operation is successfully completed, as shown in the figure\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fapi\u002Fmedia\u002Ffile\u002Fdocx_image_1770014885358_9_723e5814c2-1.jpeg\">\u003C\u002Fp>\u003Cp>The above operations can be automated via PowerShell. Modify the UserTask code as follows:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>function Invoke-ScheduledTaskComHandlerUserTask\u003Cbr>{\u003Cbr>    [CmdletBinding(SupportsShouldProcess = $True, ConfirmImpact = 'Medium')]\u003Cbr>    Param (\u003Cbr>        [Parameter(Mandatory = $True)]\u003Cbr>        [ValidateNotNullOrEmpty()]\u003Cbr>        [String]\u003Cbr>        $Command,\u003Cbr>\u003Cbr>        [Switch]\u003Cbr>        $Force\u003Cbr>    )\u003Cbr>    $ScheduledTaskCommandPath = \"HKCU:\\Software\\Classes\\CLSID\\{58fb76b9-ac85-4e55-ac04-427593b1d060}\\InprocServer32\"\u003Cbr>    if ($Force -or ((Get-ItemProperty -Path $ScheduledTaskCommandPath -Name '(default)' -ErrorAction SilentlyContinue) -eq $null)){\u003Cbr>        New-Item $ScheduledTaskCommandPath -Force |\u003Cbr>            New-ItemProperty -Name '(Default)' -Value $Command -PropertyType string -Force | Out-Null\u003Cbr>    }else{\u003Cbr>        Write-Verbose \"Key already exists, consider using -Force\"\u003Cbr>        exit\u003Cbr>    }\u003Cbr>\u003Cbr>    if (Test-Path $ScheduledTaskCommandPath) {\u003Cbr>        Write-Verbose \"Created registry entries to hijack the UserTask\"\u003Cbr>    }else{\u003Cbr>        Write-Warning \"Failed to create registry key, exiting\"\u003Cbr>        exit\u003Cbr>    }  \u003Cbr>}\u003Cbr>Invoke-ScheduledTaskComHandlerUserTask -Command \"C:\\test\\testmsg.dll\" -Verbose\u003Cbr>\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>Test system: Win7 x86\u003C\u002Fp>\u003Cp>After execution, when the user logs back in, the DLL is loaded, actual demonstration as shown in the figure\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fapi\u002Fmedia\u002Ffile\u002Fdocx_image_1770014886020_10_d43b8a3f7a-1.png\">\u003C\u002Fp>\u003Cp>Execute DLL_PROCESS_ATTACH() and DllGetClassObject() sequentially. Since DllGetClassObject() only displays a pop-up, taskhost.exe will show an error afterwards\u003C\u002Fp>\u003Cp>\u003Cstrong>Note:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>This is only a demonstration; specific solutions are not introduced here.\u003C\u002Fp>\u003Cp>At this point, the UserTask scheduled task has been successfully hijacked to load testmsg.dll at system startup.\u003C\u002Fp>\u003Ch2>0x04 UACBypass\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>Scheduled tasks have corresponding relationships with key values under HKCR:\\ in the registry. Similarly, some high-privilege programs also call key values under HKCR:\\, which creates the possibility for Bypass UAC.\u003C\u002Fp>\u003Cp>Using the same principle, by modifying key values under HKEY_CURRENT_USER\\Software\\Classes\\, the key values under HKCR:\\ are synchronously modified. If a high-privilege program calls the modified key values during its execution, Bypass UAC is naturally achieved, launching our specified program with high privileges.\u003C\u002Fp>\u003Cp>The challenge here lies in finding this high-privilege program.\u003C\u002Fp>\u003Cp>\u003Cstrong>Method:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>With the help of Process Monitor, you can view the registry, file, network, and inter-process call relationships during program execution.\u003C\u002Fp>\u003Cp>Next, use Process Monitor to reproduce the process discovered by Matt Nelson@enigma0x3.\u003C\u002Fp>\u003Ch3>1. Find a high-privilege exe\u003C\u002Fh3>\u003Cp>Matt Nelson@enigma0x3's method involves using sigcheck to view the exe's manifest.\u003C\u002Fp>\u003Cp>Parameters are as follows:\u003C\u002Fp>\u003Cp>sigcheck.exe -m c:\\windows\\system32\\eventvwr.exe\u003C\u002Fp>\u003Cp>The result is shown in the figure\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fapi\u002Fmedia\u002Ffile\u002Fdocx_image_1770014887208_11_8fca7a5c7a-1.jpeg\">\u003C\u002Fp>\u003Cp>From level=\"highestAvailable\", it is known that eventvwr.exe has high privileges\u003C\u002Fp>\u003Cp>\u003Cstrong>Note:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>A more intuitive method for judgment is provided:\u003C\u002Fp>\u003Cp>Check the file icon; if it has the UAC logo, it must be a high-privilege program, as shown in the figure\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fapi\u002Fmedia\u002Ffile\u002Fdocx_image_1770014887810_12_ce380588d0-1.jpeg\">\u003C\u002Fp>\u003Ch3>2. Use Process Monitor to view process call relationships\u003C\u002Fh3>\u003Cp>Start Process Monitor\u003C\u002Fp>\u003Cp>Run eventvwr.exe\u003C\u002Fp>\u003Cp>In Process Monitor, select Tools-Process Tree, find eventvwr.exe, right-click-Go To Event, as shown in the figure\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fapi\u002Fmedia\u002Ffile\u002Fdocx_image_1770014888517_13_125c03bb9c-1.jpeg\">\u003C\u002Fp>\u003Cp>Carefully examine the process call relationships, as shown in the figure\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fapi\u002Fmedia\u002Ffile\u002Fdocx_image_1770014889390_14_449d14e736-1.jpeg\">\u003C\u002Fp>\u003Cp>Find the following information:\u003C\u002Fp>\u003Cul>\u003Cli>eventvwr.exe has high privileges\u003C\u002Fli>\u003Cli>eventvwr.exe first queries the key HKCU\\Software\\Classes\\mscfile\\shell\\open\\command, and the result is NAME NOT FOUND\u003C\u002Fli>\u003Cli>eventvwr.exe then queries the key HKCR\\mscfile\\shell\\open\\command, and the result is SUCCESS\u003C\u002Fli>\u003C\u002Ful>\u003Ch3>3. Modification Test\u003C\u002Fh3>\u003Cp>What happens if we modify the key HKCU\\Software\\Classes\\mscfile\\shell\\open\\command so that the query result is SUCCESS?\u003C\u002Fp>\u003Cp>First, modify the key HKCU\\Software\\Classes\\mscfile\\shell\\open\\command to have the value calc.exe\u003C\u002Fp>\u003Cp>Run eventvwr.exe again and observe that calc.exe is launched\u003C\u002Fp>\u003Cp>Use Process Monitor to view the process invocation relationship, as shown in the figure\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fapi\u002Fmedia\u002Ffile\u002Fdocx_image_1770014890594_15_605e4bc47d-1.jpeg\">\u003C\u002Fp>\u003Cp>At this point, the query result for the key HKCU\\Software\\Classes\\mscfile\\shell\\open\\command is SUCCESS\u003C\u002Fp>\u003Cp>Thus, by modifying HKCU\\Software\\Classes\\mscfile\\shell\\open\\command, BypassUAC is successfully achieved, obtaining high privileges\u003C\u002Fp>\u003Cp>calc.exe has high privileges, as shown in the figure\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fapi\u002Fmedia\u002Ffile\u002Fdocx_image_1770014890951_16_e728218faa-1.jpeg\">\u003C\u002Fp>\u003Ch3>4. Additional Conclusions\u003C\u002Fh3>\u003Cp>After modifying HKCU\\Software\\Classes\\mscfile\\shell\\open\\command, the execution of all .msc files will be hijacked, such as gpedit.msc, as shown in the figure\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fapi\u002Fmedia\u002Ffile\u002Fdocx_image_1770014891201_17_215d4d5ebd-1.jpeg\">\u003C\u002Fp>\u003Cp>Following this method, I tested all high-privilege executables under system32 and have not yet discovered a UAC bypass using the same approach via the command key value, but other key values are still worth testing.\u003C\u002Fp>\u003Ch2>0x05 Defense\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>Windows 10 has patched this vulnerability, while older versions of Windows remain unpatched. Recommended defenses include:\u003C\u002Fp>\u003Cul>\u003Cli>set the UAC level to “Always Notify”\u003C\u002Fli>\u003Cli>remove the current user from the Local Administrators group\u003C\u002Fli>\u003Cli>alert on new registry entries in HKCU\\Software\\Classes\\\u003C\u002Fli>\u003C\u002Ful>\u003Cp>Quoted from https:\u002F\u002Fenigma0x3.net\u002F2016\u002F08\u002F15\u002Ffileless-uac-bypass-using-eventvwr-exe-and-registry-hijacking\u002F\u003C\u002Fp>\u003Ch2>0x06 Summary\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>There are many DLLs in scheduled tasks that can be used for persistence; monitoring these is recommended for defense.\u003C\u002Fp>\u003Cp>Using Process Monitor to find UAC bypass methods is worth further research, and new discoveries are certain to emerge.\u003C\u002Fp>\u003Cp>\u003Cstrong>Related learning materials:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>https:\u002F\u002Fenigma0x3.net\u002F2016\u002F08\u002F15\u002Ffileless-uac-bypass-using-eventvwr-exe-and-registry-hijacking\u002F\u003C\u002Fp>\u003Cp>https:\u002F\u002Fenigma0x3.net\u002F2016\u002F05\u002F25\u002Fuserland-persistence-with-scheduled-tasks-and-com-handler-hijacking\u002F\u003C\u002Fp>\u003Cp>https:\u002F\u002Fblog.gdatasoftware.com\u002F2014\u002F10\u002F23941-com-object-hijacking-the-discreet-way-of-persistence\u003C\u002Fp>\u003C\u002Fbody>\u003C\u002Fhtml>",401,"Onedaysec",8,"published","2026-02-02T07:25:19.985Z",{"title":37,"description":14,"keywords":38,"ogImage":39,"canonicalUrl":39,"noIndex":40},"Userland Registry Hijacking: Persistence & BypassUAC Techniques","userland registry hijacking, persistence, bypassuac, scheduled tasks, com handler, registry synchronization, hkcr, hkcu, privilege escalation",null,false,[],{"docs":43,"hasNextPage":40},[44,45,46,4],1024,1023,1022,{"title":39,"description":39,"image":39},"2026-07-24T15:37:10.160Z","2026-07-23T16:02:26.448Z","draft","2026-07-23T16:16:10.319Z"]