.. /Stordiag.exe
Star

Execute (EXE)

Storage diagnostic tool

Paths:

Resources:

Acknowledgements:

Detections:

Execute

  1. Once executed, Stordiag.exe will execute schtasks.exe systeminfo.exe and fltmc.exe - if stordiag.exe is copied to a folder and an arbitrary executable is renamed to one of these names, stordiag.exe will execute it.

    stordiag.exe
    Use case
    Possible defence evasion purposes.
    Privileges required
    User
    Operating systems
    Windows 10
    ATT&CK® technique
    T1218
    Tags
    Execute: EXE
  2. Once executed, Stordiag.exe will execute schtasks.exe and powershell.exe - if stordiag.exe is copied to a folder and an arbitrary executable is renamed to one of these names, stordiag.exe will execute it.

    stordiag.exe
    Use case
    Possible defence evasion purposes.
    Privileges required
    User
    Operating systems
    Windows 11
    ATT&CK® technique
    T1218
    Tags
    Execute: EXE