sdiagnhost.exe
Summary
Scripted Diagnostics Host - executes Windows troubleshooting packs and diagnostic scripts. Runs troubleshooter workflows from the Windows Troubleshooting Framework.
sdiagnhost.exe is the 545th most commonly executed Windows program in EchoTrail's dataset, observed 9,671 times across enterprise environments. It typically runs from C:\Windows\System32 and it is most often launched by svchost.exe.
Behavior
Top Paths
- C:\Windows\System3299.96%
- C:\Windows\SysWOW640.04%
Top Hashes (SHA256)
- 018a17643817c5c5e5e91e1cf202450c63cf06338070a3c61ed04b4de40518a221.89%
- 761815301a00d0b3a7bb4959a5004b623c55009ce701c6e867c96f468dc1323a16.88%
- de77562e0bdd86a685d0c930122481f69e6a9ef9f2cb023bca0dcfec05d245e516.03%
- e73e49468b9d0c870024c70bcce8d222f9812d78fef37a2f191066f1416b334910.22%
- 165968286bd97d87e360e006cc0cad67f98957427e270de70aa2928435d7aadc7.46%
- 50a816fe57195376ad30aeec2ea7968936a706508e26299302f30366cc7ff3a44.83%
- 480aafbf73786afdb295f1db4e2cc26ce962eefb38669c14672590c5e11a3c5a4.46%
- e5ec6b5b20a16383cc953ad5e478dcdf95ba46281f4fe971673c954d4145c0c43.05%
- ba4c09c3442bb1b28633b08465194b468f2ad1d4ab57484acc348e36b54657e42.96%
- eb5954d56206d64556e318dfacecb3c4cb07aefbaa9dcdfc0d912ce1477795f12.39%
Process Ancestry
Top Grandparents
- services.exe100%
Top Parents
- svchost.exe99.92%
- cmd.exe0.03%
Top Children
- conhost.exe74.58%
- csc.exe6.56%
- w32tm.exe6.12%
- PING.EXE5.69%
- regsvr32.exe2.11%
- makecab.exe0.94%
- ROUTE.EXE0.94%
- ipconfig.exe0.93%
- sc.exe0.37%
- cmd.exe0.33%
Rare or environment-specific process names are omitted from ancestry tables. Percentages are of all observed relationships.
Security Analysis
What does sdiagnhost.exe normally do?
Runs when a user or automated system triggers Windows troubleshooting packs. Executes PowerShell scripts embedded in diagnostic packages.
When is sdiagnhost.exe suspicious?
Running diagnostic packs from non-standard paths. Spawning unexpected child processes. Running frequently without user-initiated troubleshooting.
How do attackers abuse sdiagnhost.exe?
The Follina vulnerability (CVE-2022-30190) exploited MSDT through sdiagnhost.exe to execute arbitrary PowerShell code via crafted Office documents. Custom troubleshooting packs can be weaponized.
Detection guidance
Monitor sdiagnhost.exe child processes, especially PowerShell or cmd.exe. Alert on execution correlated with Office application parents (Word, Excel). Track MSDT invocations.
False positive notes
Windows Update and legitimate troubleshooting workflows invoke sdiagnhost.exe.
MITRE ATT&CK techniques
Related Processes
Ask Rocky about sdiagnhost.exe
Rocky answers questions about sdiagnhost.exe grounded in this same dataset — free, no account needed.
Need this data programmatically? The Rocky API includes 500 free lookups a month. Or just ask Rocky.
Data from EchoTrail's dataset of ~346M Windows process executions. Last extracted 2026-08-04.