Windows sdiagnhost.exe Spawns Suspicious Child Process (PowerShell/CMD/MSHTA/etc.)

Alert when sdiagnhost.exe launches high-risk child processes like PowerShell or CMD, excluding selected benign-like command patterns.

FreeReviewedSigma · High · v1
Product
windows
Category
process_creation
Author
Nextron Systems, @Kostastsale (SigmaHQ), DRL 1.1
Published
2022-06-01
Updated
2026-07-30

ATT&CK techniques

Defense Evasion
  1. Recon

  2. Resource Dev

  3. Initial Access

  4. Execution

  5. Persistence

  6. Priv Esc

  7. Cred Access

  8. Discovery

  9. Lateral Movement

  10. Collection

  11. C2

  12. Exfiltration

  13. Impact

What it detects

This rule flags Windows process creation events where sdiagnhost.exe spawns a child process commonly abused for execution, including PowerShell, CMD, MSHTA, cscript/wscript, taskkill, regsvr32, rundll32, and calc. Such parent-to-child behavior is relevant because attackers can leverage signed Windows binaries to run follow-on commands and reduce detection opportunities. It relies on process creation telemetry capturing the parent Image and child Image/CommandLine, including specific command-line substrings used to reduce matches for certain benign patterns.

Related detections9 linkedT1036 — drag to rearrange
Windows msdt.exe Execution with Suspicious Parent Process
Windows renamed dctask64.exe execution via known IMPHASH values
Suspicious Rclone Exfiltration Masquerading as wininit.exe
Suspicious Executable Running from Public Pictures Directory
Suspicious Python Execution via Renamed Synaptics Binary
Suspicious Cabinet Extraction of Masqueraded vstm Archive via extrac32
Agent Tesla Persistence via Realtek Named Scheduled Task Batch
Suspicious Interlock Fake Updater Executable Execution
Malicious DLL Execution via Wuauclt Update Handler (via process_creation)
Windows sdiagnhost.exe Spawns Suspicious Child Process (PowerShell/CMD/MSHTA/etc.)
Pivot detection · T1036 · 9 related

Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.