Potentially Suspicious ODBC Driver Registered

Rule Info

Tags
attack.persistence DEMO attack.t1003
Name
Potentially Suspicious ODBC Driver Registered
Id
e4d22291-f3d5-4b78-9a0c-a1fbaf32a6a4
Date
2023-05-23 00:00:00
Modified
2023-05-26 00:00:00
Description
Detects the registration of a new ODBC driver where the driver is located in a potentially suspicious location
Author
Nasreddine Bencherchali (Nextron Systems)
Type
Community Rule

Rule History

Title
Author
Commit
Date
feat: update more regsvr32
Nasreddine Bencherchali
2023-05-26
feat: add/update rules related to odbcconf (#4228)
cyb3rjy0t
2023-05-23