Windows File Creation: Custom Application Shim Database Files Created

Flags creation of custom Application Shim database files in AppPatch custom directories on Windows.

FreeReviewedSigma · Medium · v2
Product
windows
Category
file_event
Author
frack113, Nasreddine Bencherchali (Nextron Systems) (SigmaHQ), DRL 1.1
Published
2021-12-29
Updated
2026-07-31

ATT&CK techniques

Persistence → Priv Esc
  1. Recon

  2. Resource Dev

  3. Initial Access

  4. Execution

  5. Defense Evasion

  6. Cred Access

  7. Discovery

  8. Lateral Movement

  9. Collection

  10. C2

  11. Exfiltration

  12. Impact

What it detects

This rule flags the creation of custom Windows Application Compatibility Framework (Application Shim) database files in the default shim database directories. Attackers may use shim-based execution to persist and/or elevate privileges by triggering malicious content via application shimming. Detection relies on Windows file creation telemetry identifying newly created files whose paths contain the specified Custom and CustomSDB directories.

Related detections6 linkedT1547.009 — drag to rearrange
URL Shortcut File Created in Startup Folder for Persistence
NTFS Hard Link Creation (via process_creation)
NTFS Symbolic Link Configuration Change (via process_creation)
Windows: File creation of C:\program.exe enabling unquoted service path execution
Windows: Remote Network Share Writes to desktop.ini
Windows Desktop.ini Accessed by Uncommon Process
Windows File Creation: Custom Application Shim Database Files Created
Pivot detection · T1547.009 · 6 related

Changelog

v2
  1. v2
    Candidate ingested via manual entry.2026-07-31
  2. v1
    No changelog recorded for this version.2026-07-30

Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.