
Rule Info
Tags
attack.defense_evasion DEMO attack.t1218.008
Name
Uncommon Child Process Spawned By Odbcconf.EXE
Id
8e3c7994-131e-4ba5-b6ea-804d49113a26
Date
2023-05-22 00:00:00
Modified
None
Description
Detects an uncommon child process of "odbcconf.exe" binary which normally shouldn't have any child processes.
Author
Harjot Singh @cyb3rjy0t
Type
Community Rule
Link to Public Repo
Rule History
Title
Author
Commit
Date