Suspicious MSDT Parent Process

 Original Source: [Sigma source]
Title: Suspicious MSDT Parent Process
Status: test
Description:Detects msdt.exe executed by a suspicious parent as seen in CVE-2022-30190 / Follina exploitation
References:
  -https://twitter.com/nao_sec/status/1530196847679401984
  -https://app.any.run/tasks/713f05d2-fe78-4b9d-a744-f7c133e3fafb/
Author: Nextron Systems
Date: 2022-06-01
modified:2023-02-06
Tags:
  • -'attack.stealth'
  • -'attack.t1036'
  • -'attack.t1218'
Logsource:
  • category: process_creation
  • product: windows
Detection:
  selection_parent:
    ParentImage|endswith:
      -'\cmd.exe'
      -'\cscript.exe'
      -'\mshta.exe'
      -'\powershell.exe'
      -'\pwsh.exe'
      -'\regsvr32.exe'
      -'\rundll32.exe'
      -'\schtasks.exe'
      -'\wmic.exe'
      -'\wscript.exe'
      -'\wsl.exe'

  selection_msdt:
Image|endswith:'\msdt.exe' OriginalFileName:'msdt.exe'   condition:all of selection_*
Falsepositives:
  -Unknown
Level: high