BIOC Informational

Suspicious SDB file written to disk

Application Shims were created to allow backward compatibility of applications, which can be abused to establish persistence or elevate privileges. The creation of SDB (Shim Database) files may be indicative of this technique.

Module:
Platform Analytics
Agent event type:
File
Category:
Persistence
Status:
Enabled
ATT&CK tactics: Persistence (TA0003)
ATT&CK techniques: Event Triggered Execution: Application Shimming (T1546.011)
Indicator:

File action type = create , write AND file name = *.sdb AND file path !=~ [.].[a-zA-Z0-9]{2,3}\.[a-zA-Z0-9]{2,3}$|ApplicationConfigurationFromString|secedit.sdb|appraiser.sdb|sysmain.sdb|Sharegate|Program Files|AppData\\Roaming\\Thunderbird\\Profiles Process initiated by = powershell.exe , wscript.exe , cscript.exe , regsvcs.exe , schtasks.exe , xwizard.exe , findstr.exe , esentutl.exe , reg.exe , csc.exe , atbroker.exe , print.exe , pcwrun.exe , rpcping.exe , wsreset.exe , replace.exe , mshta.exe , bitsadmin.exe , ieexec.exe , cmd.exe , microsoft.workflow.compiler.exe , runscripthelper.exe , makecab.exe , forfiles.exe , control.exe , msbuild.exe , register-cimprovider.exe , ie4uinit.exe , sc.exe , bash.exe , sh.exe , hh.exe , mmc.exe , jsc.exe , scriptrunner.exe , odbcconf.exe , extexport.exe , msdt.exe , diskshadow.exe , extrac32.exe , eventvwr.exe , mavinject.exe , regasm.exe , gpscript.exe , rundll32.exe , regsvr32.exe , regedit.exe , msiexec.exe , presentationhost.exe , wmic.exe , runonce.exe , syncappvpublishingserver.exe , verclsid.exe , infdefaultinstall.exe , expand.exe , installutil.exe , wab.exe , dnscmd.exe , at.exe , pcalua.exe , cmdkey.exe , msconfig.exe AND cgo name != code.exe AND msiexec.exe AND Deploy-Application.exe AND BackendTaskQueueHost64.exe AND cgo cmd != *acmigration.dll,ApplyMigrationShims*

Preventable: yes