Windows Registry Modification of Application Shim Database (InstalledSDB/Custom) for Persistence
Alerts on registry changes to Windows AppCompatFlags InstalledSDB/Custom that may enable shim-based persistence.
FreeUnreviewedSigmamediumv1
windows-registry-modification-of-application-shim-database-installedsdb-custom-f-dfb5b4e8
title: Windows Registry Modification of Application Shim Database (InstalledSDB/Custom) for Persistence
id: 5a640a07-5fda-4f7f-9dbb-faf982553169
status: test
description: This rule flags Windows registry writes under the Application Compatibility/AppCompatFlags paths used for shim database configuration, specifically entries under InstalledSDB and Custom. Attackers may abuse these shim mechanisms to trigger execution of malicious content and maintain access or gain elevated privileges. Detection relies on registry set events capturing TargetObject paths that contain the specified AppCompatFlags subkeys, while excluding records with empty or null Details fields.
references:
- https://github.com/redcanaryco/atomic-red-team/blob/f339e7da7d05f6057fdfcdd3742bfcf365fee2a9/atomics/T1546.011/T1546.011.md#atomic-test-3---registry-key-creation-andor-modification-events-for-sdb
- https://www.fireeye.com/blog/threat-research/2017/05/fin7-shim-databases-persistence.html
- https://andreafortuna.org/2018/11/12/process-injection-and-persistence-using-application-shimming/
- https://github.com/SigmaHQ/sigma/blob/master/rules/windows/registry/registry_set/registry_set_persistence_shim_database.yml
author: frack113, Huntrule Team
date: 2021-12-30
modified: 2025-10-22
tags:
- attack.privilege-escalation
- attack.persistence
- attack.t1546.011
logsource:
category: registry_set
product: windows
detection:
selection:
TargetObject|contains:
- \SOFTWARE\Microsoft\Windows NT\CurrentVersion\AppCompatFlags\InstalledSDB\
- \SOFTWARE\Microsoft\Windows NT\CurrentVersion\AppCompatFlags\Custom\
filter_main_empty_string:
Details: ""
filter_main_empty_value:
Details: (Empty)
filter_main_null:
Details: null
condition: selection and not 1 of filter_main_*
falsepositives:
- Legitimate custom SHIM installations will also trigger this rule
level: medium
license: DRL-1.1
related:
- id: dfb5b4e8-91d0-4291-b40a-e3b0d3942c45
type: derived
What it detects
This rule flags Windows registry writes under the Application Compatibility/AppCompatFlags paths used for shim database configuration, specifically entries under InstalledSDB and Custom. Attackers may abuse these shim mechanisms to trigger execution of malicious content and maintain access or gain elevated privileges. Detection relies on registry set events capturing TargetObject paths that contain the specified AppCompatFlags subkeys, while excluding records with empty or null Details fields.
Known false positives
- Legitimate custom SHIM installations will also trigger this rule
Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.