
Rule Info
Tags
attack.defense_evasion DEMO attack.t1218.008
Name
Odbcconf.EXE Suspicious DLL Location
Id
6b65c28e-11f3-46cb-902a-68f2cafaf474
Date
2023-05-22 00:00:00
Modified
2023-05-26 00:00:00
Description
Detects execution of "odbcconf" where the path of the DLL being registered is located in a potentially suspicious location.
Author
Nasreddine Bencherchali (Nextron Systems)
Type
Community Rule
Link to Public Repo