Windows AppCompatFlags InstalledSDB New Shim Database in Non-Default Path
Flags persistence attempts where a shim database is registered via InstalledSDB with a non-default DatabasePath on Windows.
- Product
- windows
- Category
- registry_set
- Author
- Nasreddine Bencherchali (Nextron Systems) (SigmaHQ), DRL 1.1
- Published
- 2023-08-01
- Updated
- 2026-07-30
ATT&CK techniques
Persistence → Priv EscRecon
Resource Dev
Initial Access
Execution
Persistence
Priv Esc
Defense Evasion
Cred Access
Discovery
Lateral Movement
Collection
C2
Exfiltration
Impact
What it detects
This rule identifies the creation or modification of registry entries that install a new shim database under the AppCompatFlags\InstalledSDB key, specifically when the stored DatabasePath is set to an uncommon location. Attackers may use application shimming to establish persistence by loading malicious behavior through compatibility mechanisms. The detection relies on Windows registry set telemetry, matching the InstalledSDB registry value structure and excluding a known default location pattern.
Reporting behind it
- fireeye.comhttps://www.fireeye.com/blog/threat-research/2017/05/fin7-shim-databases-persistence.html
- andreafortuna.orghttps://andreafortuna.org/2018/11/12/process-injection-and-persistence-using-application-shimming/
- blackhat.comhttps://www.blackhat.com/docs/asia-14/materials/Erickson/Asia-14-Erickson-Persist-It-Using-And-Abusing-Microsofts-Fix-It-Patches.pdf
- github.comhttps://github.com/SigmaHQ/sigma/blob/master/rules/windows/registry/registry_set/registry_set_persistence_shim_database_uncommon_location.yml
Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.
title: Windows AppCompatFlags InstalledSDB New Shim Database in Non-Default Path
id: 15a4dc97-297e-4ddf-aca0-8d3abaa5ac63
status: test
description: This rule identifies the creation or modification of registry entries that install a new shim database under the AppCompatFlags\InstalledSDB key, specifically when the stored DatabasePath is set to an uncommon location. Attackers may use application shimming to establish persistence by loading malicious behavior through compatibility mechanisms. The detection relies on Windows registry set telemetry, matching the InstalledSDB registry value structure and excluding a known default location pattern.
references:
- https://www.fireeye.com/blog/threat-research/2017/05/fin7-shim-databases-persistence.html
- https://andreafortuna.org/2018/11/12/process-injection-and-persistence-using-application-shimming/
- https://www.blackhat.com/docs/asia-14/materials/Erickson/Asia-14-Erickson-Persist-It-Using-And-Abusing-Microsofts-Fix-It-Patches.pdf
- https://github.com/SigmaHQ/sigma/blob/master/rules/windows/registry/registry_set/registry_set_persistence_shim_database_uncommon_location.yml
author: Nasreddine Bencherchali (Nextron Systems), Huntrule Team
date: 2023-08-01
modified: 2023-08-17
tags:
- attack.privilege-escalation
- attack.persistence
- attack.t1546.011
logsource:
category: registry_set
product: windows
detection:
selection:
TargetObject|contains|all:
- \SOFTWARE\Microsoft\Windows NT\CurrentVersion\AppCompatFlags\InstalledSDB\
- \DatabasePath
filter_main_known_locations:
Details|contains: :\Windows\AppPatch\Custom
condition: selection and not 1 of filter_main_*
falsepositives:
- Unknown
level: high
license: DRL-1.1
related:
- id: 6b6976a3-b0e6-4723-ac24-ae38a737af41
type: derived