You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
This rule looks for registry activity associated with application compatibility shims, which can be leveraged by attackers for various nefarious purposes.
Additional Details
Detail
Value
Type
Templated Match
Category
Defense Evasion
Apply Risk to Entities
device_hostname, device_ip, user_username
Signal Name
Registry Keys For Creating Shim Databases
Summary Expression
Shim database registry activity detected on host: {{device_hostname}}