{"id":"ee63c85c-6d51-4d12-ad09-04e25877a947","title":"New Custom Shim Database Created","description":"Adversaries may establish persistence and/or elevate privileges by executing malicious content triggered by application shims.\nThe Microsoft Windows Application Compatibility Infrastructure/Framework (Application Shim) was created to allow for backward compatibility of software as the operating system codebase changes over time.\n","author":"frack113, Nasreddine Bencherchali (Nextron Systems)","status":"test","level":"medium","date":"2021-12-29","modified":"2023-12-06","tags":["attack.privilege-escalation","attack.persistence","attack.t1547.009"],"technique_ids":["T1547.009"],"logsource":{"product":"windows","category":"file_event"},"falsepositives":["Legitimate custom SHIM installations will also trigger this rule"],"references":["https://github.com/redcanaryco/atomic-red-team/blob/f339e7da7d05f6057fdfcdd3742bfcf365fee2a9/atomics/T1546.011/T1546.011.md#atomic-test-2---new-shim-database-files-created-in-the-default-shim-database-directory","https://www.mandiant.com/resources/blog/fin7-shim-databases-persistence","https://liberty-shell.com/sec/2020/02/25/shim-persistence/","https://andreafortuna.org/2018/11/12/process-injection-and-persistence-using-application-shimming/"],"source_path":"rules/windows/file/file_event/file_event_win_creation_new_shim_database.yml","source_sha256":"edb704b6b6ca85e556dd3257bd569c8cc4086c65b66d55c641ae3eac97bd207e","source_url":"https://github.com/anpa1200/sigma/blob/b249e9683190cffdcaf188ccbfb90bf4759844e1/rules/windows/file/file_event/file_event_win_creation_new_shim_database.yml","license":"Detection Rule License 1.1","license_url":"https://github.com/SigmaHQ/Detection-Rule-License/blob/main/LICENSE.Detection.Rules.md","yaml":"title: New Custom Shim Database Created\nid: ee63c85c-6d51-4d12-ad09-04e25877a947\nstatus: test\ndescription: |\n    Adversaries may establish persistence and/or elevate privileges by executing malicious content triggered by application shims.\n    The Microsoft Windows Application Compatibility Infrastructure/Framework (Application Shim) was created to allow for backward compatibility of software as the operating system codebase changes over time.\nreferences:\n    - https://github.com/redcanaryco/atomic-red-team/blob/f339e7da7d05f6057fdfcdd3742bfcf365fee2a9/atomics/T1546.011/T1546.011.md#atomic-test-2---new-shim-database-files-created-in-the-default-shim-database-directory\n    - https://www.mandiant.com/resources/blog/fin7-shim-databases-persistence\n    - https://liberty-shell.com/sec/2020/02/25/shim-persistence/\n    - https://andreafortuna.org/2018/11/12/process-injection-and-persistence-using-application-shimming/\nauthor: frack113, Nasreddine Bencherchali (Nextron Systems)\ndate: 2021-12-29\nmodified: 2023-12-06\ntags:\n    - attack.privilege-escalation\n    - attack.persistence\n    - attack.t1547.009\nlogsource:\n    product: windows\n    category: file_event\ndetection:\n    selection:\n        TargetFilename|contains:\n            - ':\\Windows\\apppatch\\Custom\\'\n            - ':\\Windows\\apppatch\\CustomSDB\\'\n    condition: selection\nfalsepositives:\n    - Legitimate custom SHIM installations will also trigger this rule\nlevel: medium\nregression_tests_path: regression_data/rules/windows/file/file_event/file_event_win_creation_new_shim_database/info.yml\n","validation":"yaml_parsed_not_backend_compiled_or_live_validated","techniques":[{"key":"enterprise/T1547.009","id":"T1547.009","name":"Shortcut Modification","page":"techniques/enterprise/T1547.009/"}],"data_path":"data/detection-rules/ee63c85c-6d51-4d12-ad09-04e25877a947.json","kind":"sigma"}
