LoFP LoFP / legitimate usage of \"troubleshootingpack\" cmdlet for troubleshooting purposes

Techniques

Sample rules

Troubleshooting Pack Cmdlet Execution

Description

Detects execution of “TroubleshootingPack” cmdlets to leverage CVE-2022-30190 or action similar to “msdt” lolbin (as described in LOLBAS)

Detection logic

condition: selection
selection:
  ScriptBlockText|contains|all:
  - Invoke-TroubleshootingPack
  - C:\Windows\Diagnostics\System\PCW
  - -AnswerFile
  - -Unattended