AutoRuns
AutoRuns copied to clipboard
DEV: list application shims
Steps to reproduce
dir c:\windows\AppPatch\sysmain.sdb
dir "hklm:\software\microsoft\windows nt\currentversion\appcompatflags\installedsdb"
# Custom databases are stored in:
dir C:\windows\AppPatch\custom
dir c:\windows\AppPatch\AppPatch64\Custom
dir "hklm:\software\microsoft\windows nt\currentversion\appcompatflags\custom"
Expected behavior
List if any
Actual behavior
See https://www.redcanary.com/blog/detecting-application-shimming/
They are considered as a persistence mechanism https://attack.mitre.org/wiki/Technique/T1138
Environment data
> $PSVersionTable
Name Value
---- -----
PSVersion 5.1.16299.248
PSEdition Desktop
PSCompatibleVersions {1.0, 2.0, 3.0, 4.0...}
BuildVersion 10.0.16299.248
CLRVersion 4.0.30319.42000
WSManStackVersion 3.0
PSRemotingProtocolVersion 2.3
SerializationVersion 1.1.0.1