Analytics Alerts

Browse the Cortex analytics alert reference.

Severity
Detection module
Data source
  • Uncommon execution of ODBCConf Low 1 variation

    Attackers may abuse the Odbcconf.exe Windows utility to proxy the execution of malicious DLL files.

    Activation:
    14 Days
    Training:
    30 Days
    Test:
    N/A (single event)
    Deduplication:
    1 Day
    ATT&CK tactics: Stealth (TA0005)
    ATT&CK techniques: System Binary Proxy Execution: Odbcconf (T1218.008)
    Required data: XDR Agent
    Attacker's goals: Execute arbitrary code or load malicious DLL modules undetected within Microsoft signed program from Microsoft signed process.
    Investigative actions: Check the execution command-line, in case of 'REGSVR' points to a DLL, then check it. If the command-line contains '/f' argument (for script file) check the content of the script.

    Variations

    Uncommon execution of ODBCConf to load dll directly

    High overridden

    Attackers may abuse the Odbcconf.exe Windows utility to proxy the execution of malicious DLL files. overridden