Suspicious Use of PsLogList

 Original Source: [Sigma source]
Title: Suspicious Use of PsLogList
Status: test
Description:Detects usage of the PsLogList utility to dump event log in order to extract admin accounts and perform account discovery or delete events logs
References:
  -https://research.nccgroup.com/2021/01/12/abusing-cloud-services-to-fly-under-the-radar/
  -https://www.cybereason.com/blog/deadringer-exposing-chinese-threat-actors-targeting-major-telcos
  -https://github.com/3CORESec/MAL-CL/tree/master/Descriptors/Sysinternals/PsLogList
  -https://twitter.com/EricaZelic/status/1614075109827874817
Author: Nasreddine Bencherchali (Nextron Systems)
Date: 2021-12-18
modified:2026-06-29
Tags:
  • -'attack.discovery'
  • -'attack.t1087'
  • -'attack.t1087.001'
  • -'attack.t1087.002'
Logsource:
  • category: process_creation
  • product: windows
Detection:
  selection_img:
OriginalFileName:'psloglist.exe'     - Image|endswith:
      - '\psloglist.exe'
      - '\psloglist64.exe'
      - '\psloglist64a.exe'
  selection_cli_eventlog:
    CommandLine|contains:
      -' security'
      -' application'
      -' system'

  selection_cli_flags:
    CommandLine|contains|windash:
      -' -d'
      -' -x'
      -' -s'
      -' -c'
      -' -g'

  condition:all of selection_*
Falsepositives:
  -Another tool that uses the command line switches of PsLogList
  -Legitimate use of PsLogList by an administrator
Level: medium