Windows msdt.exe Execution with Suspicious Parent Process

Alerts when msdt.exe runs under common command-and-script or utility parent processes on Windows.

FreeReviewedSigma · High · v1
Product
windows
Category
process_creation
Author
Nextron Systems (SigmaHQ), DRL 1.1
Published
2022-06-01
Updated
2026-07-30

ATT&CK techniques

Defense Evasion
  1. Recon

  2. Resource Dev

  3. Initial Access

  4. Execution

  5. Persistence

  6. Priv Esc

  7. Cred Access

  8. Discovery

  9. Lateral Movement

  10. Collection

  11. C2

  12. Exfiltration

  13. Impact

What it detects

This rule flags executions of msdt.exe where the process is launched by a potentially suspicious parent such as cmd.exe, powershell.exe/pwsh.exe, mshta.exe, regsvr32.exe, rundll32.exe, wmic.exe, schtasks.exe, wscript.exe, or wsl.exe. Attackers may use MSDT execution to blend into legitimate Windows tooling while achieving code execution. It relies on Windows process creation telemetry that includes ParentImage and the invoked executable (Image/OriginalFileName).

Related detections9 linkedT1036 — drag to rearrange
Windows sdiagnhost.exe Spawns Suspicious Child Process (PowerShell/CMD/MSHTA/etc.)
Windows renamed dctask64.exe execution via known IMPHASH values
Suspicious Rclone Exfiltration Masquerading as wininit.exe
Suspicious Executable Running from Public Pictures Directory
Suspicious Python Execution via Renamed Synaptics Binary
Suspicious Cabinet Extraction of Masqueraded vstm Archive via extrac32
Agent Tesla Persistence via Realtek Named Scheduled Task Batch
Suspicious Interlock Fake Updater Executable Execution
Malicious DLL Execution via Wuauclt Update Handler (via process_creation)
Windows msdt.exe Execution with Suspicious Parent Process
Pivot detection · T1036 · 9 related

Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.