 
    
    
    Rule Info
Name
                    
                    
                        Suspicious Response File Execution Via Odbcconf.EXE
                    
                
            Author
                    
                    
                        Nasreddine Bencherchali (Nextron Systems)
                    
                
            Description
                    
                    
                        Detects execution of "odbcconf" with the "-f" flag in order to load a response file with a non-".rsp" extension.
                    
                
            Date
                    
                    
                        2023-05-22 00:00:00
                    
                
            Modified
                    
                    
                        2024-03-13 00:00:00
                    
                
            Id
                    
                    
                        2d32dd6f-3196-4093-b9eb-1ad8ab088ca5
                    
                
            Tags
                    
                    
                        attack.defense-evasion attack.t1218.008
                    
                
            Type
                Community Rule
            Link to Public Repo
                
            Rule History
Author
                
                
                
                Title
                
                
                
                Date
                
                
                
                Commit
                
                
            phantinuss
                
                
                
                Merge PR #5630 from @phantinuss - Revert "chore: improve windash order in modifiers"
                
                
                
                2025-08-28
                
                
                
                
                
                
            phantinuss
                
                
                
                Merge PR #5628 from @phantinuss - chore: improve windash order in modifiers
                
                
                
                2025-08-26
                
                
                
                
                
                
            github-actions[bot]
                
                
                
                Merge PR #5177 from @nasbench - promote older rules status from `experimental` to `test`
                
                
                
                2025-02-03
                
                
                
                
                
                
            Nasreddine Bencherchali
                
                
                
                Merge PR #4950 from @nasbench - Comply With v2 Spec Changes
                
                
                
                2024-08-12
                
                
                
                
                
                
            frack113
                
                
                
                Merge PR #4767 from @frack113 - Update additional rules to use the `windash` modifier
                
                
                
                2024-03-15
                
                
                
                
                
                
            