LoFP LoFP / t1218.008

t1218.008

TitleTags
false positives may be present and filtering may need to occur based on legitimate application usage. filter as needed.
false positives will be present as this is meant to assist with filtering and tuning.
in rare occurrences where \"odbcconf\" crashes. it might spawn a \"werfault\" process
legitimate dlls being registered via \"odbcconf\" will generate false positives. investigate the path of the dll and its content to determine if the action is authorized.
legitimate driver dlls being registered via \"odbcconf\" will generate false positives. investigate the path of the dll and its contents to determine if the action is authorized.
other child processes will depend on the dll being registered by actions like \"regsvr\". in case where the dlls have external calls (which should be rare). other child processes might spawn and additional filters need to be applied.
the rule is looking for any usage of response file, which might generate false positive when this function is used legitimately. investigate the contents of the \".rsp\" file to determine if it is malicious and apply additional filters if necessary.
unlikely