Skip to content

Latest commit

 

History

History
37 lines (30 loc) · 1.25 KB

MATCH-S00545.md

File metadata and controls

37 lines (30 loc) · 1.25 KB

Rules: Registry Keys For Creating Shim Databases

Description

This rule looks for registry activity associated with application compatibility shims, which can be leveraged by attackers for various nefarious purposes.

Additional Details

Detail Value
Type Templated Match
Category Defense Evasion
Apply Risk to Entities device_hostname, device_ip, user_username
Signal Name Registry Keys For Creating Shim Databases
Summary Expression Shim database registry activity detected on host: {{device_hostname}}
Score/Severity Static: 3
Enabled by Default True
Prototype False
Tags _mitreAttackTactic:TA0005, _mitreAttackTactic:TA0003, _mitreAttackTactic:TA0004, _mitreAttackTechnique:T1112, _mitreAttackTechnique:T1546, _mitreAttackTechnique:T1546.011

Vendors and Products

Fields Used

Origin Field
Normalized Schema application
Normalized Schema baseImage
Normalized Schema device_hostname
Normalized Schema device_ip
Normalized Schema file_path
Normalized Schema lower
Normalized Schema metadata_deviceEventId
Normalized Schema metadata_product
Normalized Schema metadata_vendor
Normalized Schema user_username