Clankerusecase
MITRE ATT&CK detection coverage
← Back to main site
Home/ MITRE Matrix/ Privilege Escalation/ T1546.011

T1546.011Application Shimming

T1546.011 — Application Shimming is a MITRE ATT&CK technique in the Privilege Escalation tactic. Clankerusecase tracks 3 detection use cases covering it.

Privilege EscalationPersistence
View on the matrix → Filter Detection Library MITRE official spec ↗
3Use cases
0Articles
0Sub-techniques
2Tactics

Use cases covering this technique (3)

Registry Keys for Creating SHIM Databases ESCU actions · alerting P Shim Database File Creation ESCU actions · alerting P Shim Database Installation With Suspicious Parameters ESCU actions · alerting P