Suspicious Cabinet File Execution Via Msdt.EXE — Detection Rule

Detects execution of msdt.exe using the "cab" flag which could indicates suspicious diagcab files with embedded answer files leveraging CVE-2022-30190

Read the full analysis on IntelFusions