Uncommon Extension Shim Database Installation Via Sdbinst.EXE (18ee686c-38a3-4f65-9f44-48a077141f42)
Detects installation of a potentially suspicious new shim with an uncommon extension using sdbinst.exe. Adversaries may establish persistence and/or elevate privileges by executing malicious content triggered by application shims