AN0051
Analytic 0051
Windows
Correlated modification of AppCompat registry keys and execution of sdbinst.exe to install custom shim databases. Followed by DLL injection via shim behavior into target application processes.
WinEventLog:Security
EventCode=4657
WinEventLog:Sysmon
EventCode=1
WinEventLog:Sysmon
EventCode=7
WinEventLog:Sysmon
EventCode=11
[CustomShimPathAllowlist]
Filter out known-good .sdb paths in AppPatch\Custom folders
[TimeWindow]
Tunable window for correlating registry modification and sdbinst.exe execution
[DLLInjectionTarget]
Expected target applications or binaries for injected DLLs
[UserContext]
Limit alerting to admin or SYSTEM-context initiated shim installations
[ShimCommandLinePattern]
Expected or benign sdbinst.exe command-line patterns to exclude