LoFP LoFP / utilization of this tool should not be seen in enterprise environment

Techniques

Sample rules

Visual Basic Command Line Compiler Usage

Description

Detects successful code compilation via Visual Basic Command Line Compiler that utilizes Windows Resource to Object Converter.

Detection logic

condition: selection
selection:
  Image|endswith: \cvtres.exe
  ParentImage|endswith: \vbc.exe