Potentially Suspicious ODBC Driver Registered

Rule Info

Name
Potentially Suspicious ODBC Driver Registered
Author
Nasreddine Bencherchali (Nextron Systems)
Description
Detects the registration of a new ODBC driver where the driver is located in a potentially suspicious location
Date
2023-05-23 00:00:00
Modified
2023-08-17 00:00:00
Id
e4d22291-f3d5-4b78-9a0c-a1fbaf32a6a4
Tags
attack.persistence attack.t1003 DEMO
Type
Community Rule

Rule History

Author
Title
Date
Commit
frack113
Refractor registry_set rules
2023-08-17
Nasreddine Bencherchali
feat: update more regsvr32
2023-05-26
cyb3rjy0t
feat: add/update rules related to odbcconf (#4228)
2023-05-23