{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/tags/appcompat/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":[],"_cs_cves":[],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":[],"_cs_severities":["medium"],"_cs_tags":["persistence","windows","appcompat"],"_cs_type":"advisory","_cs_vendors":[],"content_html":"\u003cp\u003eThe Windows Application Compatibility (AppCompat) framework is designed to allow legacy applications to function correctly on newer versions of the Windows operating system. This framework utilizes Shim Database (.sdb) files to apply compatibility fixes or patches to specific processes. Threat actors have been observed abusing this functionality to gain persistence and execute arbitrary code by installing custom, malicious shim databases. Once registered in the Windows Registry, these databases can force the loading of malicious code into legitimate processes whenever they are executed. This technique is particularly effective as it operates at the system level and can be used to achieve stealthy, persistent execution. Defenders should monitor registry modifications within the AppCompatFlags subtree to detect the registration of unauthorized .sdb files.\u003c/p\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful abuse of Application Compatibility Shim databases allows attackers to achieve persistent execution with the privileges of the host process, potentially leading to unauthorized access, privilege escalation, or data exfiltration. This technique can be applied across various Windows environments, and its stealthy nature makes it a valuable persistence mechanism for threat actors seeking to maintain long-term access to compromised systems.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eDeploy the provided Sigma rule to monitor registry modifications within the 'AppCompatFlags\\Custom' registry key for the creation or modification of .sdb entries.\u003c/li\u003e\n\u003cli\u003eEstablish a baseline of legitimate shim database registrations within the environment to reduce false positives.\u003c/li\u003e\n\u003cli\u003eInvestigate any registry modification events originating from unknown or unsigned processes that target 'AppCompatFlags\\Custom'.\u003c/li\u003e\n\u003cli\u003eRegularly audit system registry paths associated with 'AppCompatFlags' to identify and remove unauthorized or suspicious .sdb entries.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-08-31T17:52:33Z","date_published":"2026-08-31T17:52:33Z","id":"https://feed.craftedsignal.io/briefs/2026-08-shim-persistence/","summary":"Attackers utilize the Windows Application Compatibility Shim (AppCompat) mechanism to achieve persistence and arbitrary code execution by registering malicious shim databases.","title":"Abuse of Application Compatibility Shim Databases for Persistence","url":"https://feed.craftedsignal.io/briefs/2026-08-shim-persistence/"}],"language":"en","title":"CraftedSignal Threat Feed - Appcompat","version":"https://jsonfeed.org/version/1.1"}