BIOCs
Browse the Cortex behavioral indicator of compromise (BIOC) detection rules.
2 BIOCs match the current filters. tactic: TA0004 ✕ technique: T1546 ✕
Download CSV Show ATT&CK heatmapManipulation of the sticky keys file Medium Privilege Escalation
Possible login bypass attack.
Indicator:File action type = create , write AND file path = *:\Windows\System32 , *:\Windows\Syswow64 AND file name = sethc.exe
ATT&CK tactics: Privilege Escalation (TA0004)ATT&CK techniques: Event Triggered Execution: Accessibility Features (T1546.008)- Preventable:
- Yes
- Source:
- Palo Alto Networks
- Updated:
- 2026-02-11
Shim database file access Informational Persistence
An attacker may install a malicious SDB (shim database) file on disk for privilege escalation and persistence.
Indicator:File action type = create , rename , write AND file path = *\windows\apppatch\custom\*
ATT&CK tactics: Persistence (TA0003) Privilege Escalation (TA0004)ATT&CK techniques: Event Triggered Execution: Application Shimming (T1546.011)- Preventable:
- Yes
- Source:
- Palo Alto Networks
- Updated:
- 2026-08-23