MSDT Execution Via Answer File

 Original Source: [Sigma source]
Title: MSDT Execution Via Answer File
Status: test
Description:Detects execution of "msdt.exe" using an answer file which is simulating the legitimate way of calling msdt via "pcwrun.exe" (For example from the compatibility tab).
References:
  -https://lolbas-project.github.io/lolbas/Binaries/Msdt/
Author: Nasreddine Bencherchali (Nextron Systems)
Date: 2022-06-13
modified:2025-10-29
Tags:
  • -'attack.stealth'
  • -'attack.t1218'
  • -'attack.execution'
Logsource:
  • category: process_creation
  • product: windows
Detection:
  selection:
    Image|endswith: '\msdt.exe'
    CommandLine|contains: '\WINDOWS\diagnostics\index\PCWDiagnostic.xml'
    CommandLine|contains|windash: ' -af '
  filter_main_pcwrun:
    ParentImage|endswith: '\pcwrun.exe'
  condition:selection and not 1 of filter_main_*
Falsepositives:
  -Possible undocumented parents of "msdt" other than "pcwrun".
Level: high