Windows Registry: New AppCompatFlags custom shim databases targeting system processes
Alerts on Windows registry writes to AppCompatFlags Custom shim paths targeting common system processes.
- Product
- windows
- Category
- registry_set
- Author
- Nasreddine Bencherchali (Nextron Systems) (SigmaHQ), DRL 1.1
- Published
- 2023-08-01
- Updated
- 2026-07-30
ATT&CK techniques
Persistence → Priv EscRecon
Resource Dev
Initial Access
Execution
Persistence
Priv Esc
Defense Evasion
Cred Access
Discovery
Lateral Movement
Collection
C2
Exfiltration
Impact
What it detects
This rule flags registry entries created under the AppCompatFlags Custom shim path, where the TargetObject points to shim database activity associated with well-known Windows processes. Attackers may use shim databases to influence process behavior for persistence or process injection. Telemetry relies on Windows registry set events capturing the TargetObject path being written.
Reporting behind it
- trustwave.comhttps://www.trustwave.com/en-us/resources/blogs/spiderlabs-blog/pillowmint-fin7s-monkey-thief/
- fireeye.comhttps://www.fireeye.com/blog/threat-research/2017/05/fin7-shim-databases-persistence.html
- github.comhttps://github.com/SigmaHQ/sigma/blob/master/rules/windows/registry/registry_set/registry_set_persistence_shim_database_susp_application.yml
Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.
title: "Windows Registry: New AppCompatFlags custom shim databases targeting system processes"
id: e0252761-752a-4fae-86dc-586a4be463ce
status: test
description: This rule flags registry entries created under the AppCompatFlags Custom shim path, where the TargetObject points to shim database activity associated with well-known Windows processes. Attackers may use shim databases to influence process behavior for persistence or process injection. Telemetry relies on Windows registry set events capturing the TargetObject path being written.
references:
- https://www.trustwave.com/en-us/resources/blogs/spiderlabs-blog/pillowmint-fin7s-monkey-thief/
- https://www.fireeye.com/blog/threat-research/2017/05/fin7-shim-databases-persistence.html
- https://github.com/SigmaHQ/sigma/blob/master/rules/windows/registry/registry_set/registry_set_persistence_shim_database_susp_application.yml
author: Nasreddine Bencherchali (Nextron Systems), Huntrule Team
date: 2023-08-01
modified: 2023-12-06
tags:
- attack.privilege-escalation
- attack.persistence
- attack.t1546.011
logsource:
category: registry_set
product: windows
detection:
selection:
TargetObject|contains: \SOFTWARE\Microsoft\Windows NT\CurrentVersion\AppCompatFlags\Custom\
TargetObject|endswith:
- \csrss.exe
- \dllhost.exe
- \explorer.exe
- \RuntimeBroker.exe
- \services.exe
- \sihost.exe
- \svchost.exe
- \taskhostw.exe
- \winlogon.exe
- \WmiPrvSe.exe
condition: selection
falsepositives:
- Unknown
level: high
license: DRL-1.1
related:
- id: bf344fea-d947-4ef4-9192-34d008315d3a
type: derived