Title:MSDT Execution Via Answer File Status:test Description:Detects execution of "msdt.exe" using an answer file which is simulating the legitimate way of calling msdt via "pcwrun.exe" (For example from the compatibility tab).
References: -https://lolbas-project.github.io/lolbas/Binaries/Msdt/ Author: Nasreddine Bencherchali (Nextron Systems) Date: 2022-06-13 modified:2025-10-29 Tags:
-'attack.stealth'
-'attack.t1218'
-'attack.execution'
Logsource:
category: process_creation
product: windows
Detection: selection: Image|endswith:
'\msdt.exe' CommandLine|contains:
'\WINDOWS\diagnostics\index\PCWDiagnostic.xml' CommandLine|contains|windash:
' -af ' filter_main_pcwrun: ParentImage|endswith:
'\pcwrun.exe' condition:selection and not 1 of filter_main_* Falsepositives:
-Possible undocumented parents of "msdt" other than "pcwrun". Level:high