BIOC Informational

Shim database file access

An attacker may install a malicious SDB (shim database) file on disk for privilege escalation and persistence.

Module:
Platform Analytics
Agent event type:
File
Category:
Persistence
Status:
Enabled
ATT&CK tactics: Persistence (TA0003) Privilege Escalation (TA0004)
ATT&CK techniques: Event Triggered Execution: Application Shimming (T1546.011)
Indicator:

File action type = create , rename , write AND file path = *\windows\apppatch\custom\*

Preventable: yes