{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","feed_url":"https://feed.craftedsignal.io/products/microsoft-diagnostics-troubleshooting-wizard/feed.json","home_page_url":"https://feed.craftedsignal.io/","items":[{"_cs_actors":[],"_cs_cpes":[],"_cs_cves":[{"cvss":7.8,"id":"CVE-2022-30190"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["Microsoft Diagnostics Troubleshooting Wizard","Windows"],"_cs_severities":["high"],"_cs_tags":["defense-evasion","proxy-execution","msdt"],"_cs_type":"advisory","_cs_vendors":["Microsoft"],"content_html":"\u003cp\u003eThe Microsoft Diagnostics Troubleshooting Wizard (MSDT) is a legitimate Windows tool designed to diagnose and resolve system issues. However, attackers can abuse MSDT to execute malicious commands or binaries by manipulating its process arguments. This technique, often referred to as \u0026quot;living off the land,\u0026quot; allows adversaries to bypass traditional security measures by proxying their malicious actions through a trusted system utility. This particular rule focuses on identifying instances where MSDT is used with suspicious arguments or from unusual locations. Observed exploitation has been linked to the abuse of the \u0026quot;Follina\u0026quot; vulnerability (CVE-2022-30190), although this rule is designed to detect broader MSDT abuse patterns, not just specific CVE exploitation. This technique allows attackers to evade detection by blending in with legitimate system activity and potentially gaining elevated privileges.\u003c/p\u003e\n\u003ch2 id=\"attack-chain\"\u003eAttack Chain\u003c/h2\u003e\n\u003col\u003e\n\u003cli\u003eThe attacker gains initial access via an arbitrary code execution vulnerability or other means.\u003c/li\u003e\n\u003cli\u003eThe attacker crafts a malicious payload designed to execute commands via MSDT. This payload often involves manipulating process arguments to achieve code execution.\u003c/li\u003e\n\u003cli\u003eA process such as \u003ccode\u003ecmd.exe\u003c/code\u003e, \u003ccode\u003epowershell.exe\u003c/code\u003e, or \u003ccode\u003emshta.exe\u003c/code\u003e is used to launch \u003ccode\u003emsdt.exe\u003c/code\u003e with malicious arguments. This may include arguments like \u003ccode\u003eIT_RebrowseForFile=*\u003c/code\u003e, \u003ccode\u003e*FromBase64*\u003c/code\u003e, or arguments designed to trigger the execution of arbitrary code.\u003c/li\u003e\n\u003cli\u003e\u003ccode\u003emsdt.exe\u003c/code\u003e is executed with the malicious arguments, effectively proxying the attacker's commands through a trusted system utility.\u003c/li\u003e\n\u003cli\u003eThe attacker's commands are executed within the context of \u003ccode\u003emsdt.exe\u003c/code\u003e, potentially allowing them to bypass security restrictions or evade detection.\u003c/li\u003e\n\u003cli\u003eThe attacker may use the proxied execution to download and execute additional payloads, establish persistence, or perform other malicious activities.\u003c/li\u003e\n\u003cli\u003eThe attacker leverages the established foothold to move laterally within the network, compromising additional systems and escalating privileges.\u003c/li\u003e\n\u003cli\u003eThe final objective is achieved, such as data exfiltration, ransomware deployment, or disruption of critical systems.\u003c/li\u003e\n\u003c/ol\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation of MSDT proxy execution can lead to a wide range of adverse impacts, including arbitrary code execution, privilege escalation, data theft, and system compromise. The use of a trusted system utility like MSDT makes it difficult to detect and prevent these attacks, potentially allowing attackers to operate undetected for extended periods. Specific impact depends on the attacker's goals but may include widespread data loss, financial damage, and reputational harm.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eDeploy the \u0026quot;Suspicious Microsoft Diagnostics Wizard Execution\u0026quot; Sigma rule to your SIEM to detect suspicious \u003ccode\u003emsdt.exe\u003c/code\u003e executions.\u003c/li\u003e\n\u003cli\u003eMonitor process creation events for \u003ccode\u003emsdt.exe\u003c/code\u003e with suspicious command-line arguments, such as \u003ccode\u003eIT_RebrowseForFile=*\u003c/code\u003e, \u003ccode\u003e*FromBase64*\u003c/code\u003e, or \u003ccode\u003e*/../../../*\u003c/code\u003e (see Sigma rule).\u003c/li\u003e\n\u003cli\u003eInvestigate any instances of \u003ccode\u003emsdt.exe\u003c/code\u003e being launched by unexpected parent processes, such as \u003ccode\u003ecmd.exe\u003c/code\u003e, \u003ccode\u003epowershell.exe\u003c/code\u003e, or \u003ccode\u003emshta.exe\u003c/code\u003e (see Sigma rule).\u003c/li\u003e\n\u003cli\u003eEnsure that \u003ccode\u003emsdt.exe\u003c/code\u003e is running from a legitimate file path (\u003ccode\u003e?:\\\\Windows\\\\system32\\\\msdt.exe\u003c/code\u003e or \u003ccode\u003e?:\\\\Windows\\\\SysWOW64\\\\msdt.exe\u003c/code\u003e) and investigate any deviations.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2024-01-02T12:00:00Z","date_published":"2024-01-02T12:00:00Z","id":"https://feed.craftedsignal.io/briefs/2024-01-02-msdt-proxy-execution/","summary":"The Microsoft Diagnostics Troubleshooting Wizard (MSDT) can be abused to proxy malicious command or binary execution via malicious process arguments, potentially leading to defense evasion and arbitrary code execution.","title":"Microsoft Diagnostics Troubleshooting Wizard (MSDT) Proxy Execution Abuse","url":"https://feed.craftedsignal.io/briefs/2024-01-02-msdt-proxy-execution/"}],"language":"en","title":"CraftedSignal Threat Feed - Microsoft Diagnostics Troubleshooting Wizard","version":"https://jsonfeed.org/version/1.1"}