LoFP LoFP / in rare occurrences where \"odbcconf\" crashes. it might spawn a \"werfault\" process

Techniques

Sample rules

Uncommon Child Process Spawned By Odbcconf.EXE

Description

Detects an uncommon child process of “odbcconf.exe” binary which normally shouldn’t have any child processes.

Detection logic

condition: selection
selection:
  ParentImage|endswith: \odbcconf.exe