Suspicious MSDT Parent Process — Detection Rule

Detects msdt.exe executed by a suspicious parent as seen in CVE-2022-30190 / Follina exploitation

Read the full analysis on IntelFusions