{"id":"T1547.009","name":"Shortcut Modification","url":"https://attack.mitre.org/techniques/T1547/009","tactics":["persistence","privilege-escalation"],"platforms":["Windows"],"live":true,"revoked":false,"deprecated":false,"revoked_by":null,"detection_strategies":[{"id":"DET0180","stix_id":"x-mitre-detection-strategy--300931b1-bd28-4e91-ba6e-585f3563e8e4","name":"Detection Strategy for T1547.009 – Shortcut Modification (Windows)","url":"https://attack.mitre.org/detectionstrategies/DET0180","analytics":[{"id":"AN0510","stix_id":"x-mitre-analytic--5f9fdff8-55ed-4b1e-8889-46b376ce7149","name":"Analytic 0510","description":"Detection correlates file creation or modification of `.lnk` (shortcut) files in autostart locations with anomalous parent-child process lineage or unsigned binaries. Defenders should watch for LNK creation/modification events outside of known software installations, patch events, or OS updates. Flag shortcut targets pointing to suspicious locations or unknown binaries, particularly those written by script interpreters or spawned from phishing delivery chains.","url":"https://attack.mitre.org/detectionstrategies/DET0180#AN0510","platforms":["Windows"],"log_source_references":[{"name":"WinEventLog:Sysmon","channel":"EventCode=11","data_component":"DC0039","data_component_name":"File Creation","log_source_slug":"wineventlog-sysmon"},{"name":"WinEventLog:Sysmon","channel":"EventCode=2","data_component":"DC0061","data_component_name":"File Modification","log_source_slug":"wineventlog-sysmon"},{"name":"WinEventLog:Sysmon","channel":"EventCode=1","data_component":"DC0032","data_component_name":"Process Creation","log_source_slug":"wineventlog-sysmon"},{"name":"WinEventLog:Sysmon","channel":"EventCode=15","data_component":"DC0059","data_component_name":"File Metadata","log_source_slug":"wineventlog-sysmon"}],"mutable_elements":[{"field":"TargetPathRegex","description":"Tunable regex to flag suspicious shortcut target paths (e.g., temp folder, base64 in target, unusual executable names)"},{"field":"TimeWindow","description":"Time window used to correlate shortcut creation with process execution (e.g., 5-minute window)"},{"field":"UserContextScope","description":"Filter for expected administrative installs versus end-user initiated shortcut creation"},{"field":"ZoneIdentifierThreshold","description":"Configurable value to filter LNK files tagged with external source markers (e.g., ZoneId=3 for Internet)"}],"live":true,"detection_strategies":["DET0180"],"techniques":["T1547.009"]}],"live":true,"version":"1.0","techniques":["T1547.009"]}],"sigma_rules":[{"id":"35bc7e28-ee6b-492f-ab04-da58fcf6402e","title":"Windows Network Access Suspicious desktop.ini Action","author":"Tim Shelton (HAWK.IO)","status":"test","level":"medium","date":"2021-12-06","modified":"2022-01-16","description":"Detects unusual processes accessing desktop.ini remotely over network share, which can be leveraged to alter how Explorer displays a folder's content (i.e. renaming files) without changing them on disk.","references":["https://isc.sans.edu/forums/diary/Desktopini+as+a+postexploitation+tool/25912/"],"logsource":{"product":"windows","service":"security"},"tags":["attack.privilege-escalation","attack.persistence","attack.t1547.009"],"path":"rules/windows/builtin/security/win_security_net_share_obj_susp_desktop_ini.yml","techniques":["T1547.009"],"cves":[]},{"id":"81315b50-6b60-4d8f-9928-3466e1022515","title":"Desktop.INI Created by Uncommon Process","author":"Maxime Thiebaut (@0xThiebaut), Tim Shelton (HAWK.IO)","status":"test","level":"medium","date":"2020-03-19","modified":"2025-12-09","description":"Detects unusual processes accessing desktop.ini, which can be leveraged to alter how Explorer displays a folder's content (i.e. renaming files) without changing them on disk.","references":["https://isc.sans.edu/forums/diary/Desktopini+as+a+postexploitation+tool/25912/"],"logsource":{"product":"windows","category":"file_event"},"tags":["attack.privilege-escalation","attack.persistence","attack.t1547.009"],"path":"rules/windows/file/file_event/file_event_win_desktop_ini_created_by_uncommon_process.yml","techniques":["T1547.009"],"cves":[]},{"id":"8c3c76ca-8f8b-4b1d-aaf3-81aebcd367c9","title":"Creation Exe for Service with Unquoted Path","author":"frack113","status":"test","level":"high","date":"2021-12-30","modified":null,"description":"Adversaries may execute their own malicious payloads by hijacking vulnerable file path references.\nAdversaries can take advantage of paths that lack surrounding quotations by placing an executable in a higher level directory within the path, so that Windows will choose the adversary's executable to launch.\n","references":["https://github.com/redcanaryco/atomic-red-team/blob/f339e7da7d05f6057fdfcdd3742bfcf365fee2a9/atomics/T1574.009/T1574.009.md"],"logsource":{"product":"windows","category":"file_event"},"tags":["attack.privilege-escalation","attack.persistence","attack.t1547.009"],"path":"rules/windows/file/file_event/file_event_win_creation_unquoted_service_path.yml","techniques":["T1547.009"],"cves":[]},{"id":"ee63c85c-6d51-4d12-ad09-04e25877a947","title":"New Custom Shim Database Created","author":"frack113, Nasreddine Bencherchali (Nextron Systems)","status":"test","level":"medium","date":"2021-12-29","modified":"2023-12-06","description":"Adversaries may establish persistence and/or elevate privileges by executing malicious content triggered by application shims.\nThe Microsoft Windows Application Compatibility Infrastructure/Framework (Application Shim) was created to allow for backward compatibility of software as the operating system codebase changes over time.\n","references":["https://github.com/redcanaryco/atomic-red-team/blob/f339e7da7d05f6057fdfcdd3742bfcf365fee2a9/atomics/T1546.011/T1546.011.md#atomic-test-2---new-shim-database-files-created-in-the-default-shim-database-directory","https://www.mandiant.com/resources/blog/fin7-shim-databases-persistence","https://liberty-shell.com/sec/2020/02/25/shim-persistence/","https://andreafortuna.org/2018/11/12/process-injection-and-persistence-using-application-shimming/"],"logsource":{"product":"windows","category":"file_event"},"tags":["attack.privilege-escalation","attack.persistence","attack.t1547.009"],"path":"rules/windows/file/file_event/file_event_win_creation_new_shim_database.yml","techniques":["T1547.009"],"cves":[]}],"kev_cves":[{"cveID":"CVE-2024-21762","state":"mapped","mapping_types":["secondary_impact"]}],"_built":"2026-08-24 19:45 UTC","_attack_version":"19.2","_sigma_commit":"da9bb07d642a2826e89702445d32c795209ec108"}