Windows: Flag SettingSyncHost.exe used to execute RoamDiag.cmd from cmd.exe

Flags non-System32/SysWOW64 processes spawned by SettingSyncHost.exe running RoamDiag.cmd via cmd.exe /c -outputpath.

FreeReviewedSigma · High · v2
Product
windows
Category
process_creation
Author
Anton Kutepov, oscd.community (SigmaHQ), DRL 1.1
Published
2020-02-05
Updated
2026-07-31

ATT&CK techniques

Execution → Defense Evasion
  1. Recon

  2. Resource Dev

  3. Initial Access

  4. Cred Access

  5. Discovery

  6. Lateral Movement

  7. Collection

  8. C2

  9. Exfiltration

  10. Impact

What it detects

This rule identifies executions where SettingSyncHost.exe launches a command chain that includes cmd.exe /c and a specific RoamDiag.cmd invocation with -outputpath. It matters because this behavior can indicate abuse of a legitimate Windows utility to run an attacker-controlled or hijacked binary indirectly. The detection relies on process creation telemetry, specifically the parent process command line and the child process image path being outside standard system directories.

Changelog

v2
  1. v2
    Candidate ingested via manual entry.2026-07-31
  2. v1
    No changelog recorded for this version.2026-07-30

Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.