BIOC
Informational
✕
Shim database file access
An attacker may install a malicious SDB (shim database) file on disk for privilege escalation and persistence.
- Module:
- Platform Analytics
- Agent event type:
- File
- Category:
- Persistence
- Status:
- Enabled
ATT&CK tactics: Persistence (TA0003) Privilege Escalation (TA0004)
ATT&CK techniques: Event Triggered Execution: Application Shimming (T1546.011)
Indicator:
File action type = create , rename , write AND file path = *\windows\apppatch\custom\*
Preventable: yes