Windows PDQ Deploy Console Execution

Alerts on Windows execution of PDQ Deploy Console (PDQDeployConsole.exe) based on process metadata.

FreeReviewedSigma · Medium · v1
Product
windows
Category
process_creation
Author
frack113 (SigmaHQ), DRL 1.1
Published
2022-10-01
Updated
2026-07-30

ATT&CK techniques

Execution → Lateral Movement
  1. Recon

  2. Resource Dev

  3. Initial Access

  4. Persistence

  5. Priv Esc

  6. Defense Evasion

  7. Cred Access

  8. Discovery

  9. Collection

  10. C2

  11. Exfiltration

  12. Impact

What it detects

This rule flags process creation events where PDQ Deploy Console (PDQDeployConsole.exe) is launched on Windows. Attackers can use remote administration tools to support lateral movement and execution across managed endpoints. The detection relies on process creation telemetry containing product/company metadata and the OriginalFileName field values associated with PDQ Deploy.

Related detections3 linkedT1072 — drag to rearrange
Windows SRP restricted application access (Event IDs 865, 866, 867, 868, 882)
Radmin Viewer Utility Execution on Windows (Process Creation)
Windows Process Creation: Suspicious Microsoft Csi.exe or Rcsi.exe with C# Execution Capability
Windows PDQ Deploy Console Execution
Pivot detection · T1072 · 3 related

Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.