Analytics Alerts
Browse the Cortex analytics alert reference.
1 alert match the current filters. tactic: TA0005 ✕
Download CSV Show ATT&CK heatmapUncommon execution of ODBCConf Low 1 variation
Attackers may abuse the Odbcconf.exe Windows utility to proxy the execution of malicious DLL files.
- Activation:
- 14 Days
- Training:
- 30 Days
- Test:
- N/A (single event)
- Deduplication:
- 1 Day
ATT&CK tactics: Stealth (TA0005)ATT&CK techniques: System Binary Proxy Execution: Odbcconf (T1218.008)Required data: XDR AgentAttacker's goals: Execute arbitrary code or load malicious DLL modules undetected within Microsoft signed program from Microsoft signed process.Investigative actions: Check the execution command-line, in case of 'REGSVR' points to a DLL, then check it. If the command-line contains '/f' argument (for script file) check the content of the script.Variations
Uncommon execution of ODBCConf to load dll directly
High overridden
Attackers may abuse the Odbcconf.exe Windows utility to proxy the execution of malicious DLL files. overridden