PUA - Sysinternal Tool Execution - Registry

 Original Source: [Sigma source]
Title: PUA - Sysinternal Tool Execution - Registry
Status: test
Description:Detects the execution of a Sysinternals Tool via the creation of the "accepteula" registry key
References:
  -https://twitter.com/Moti_B/status/1008587936735035392
Author: Markus Neis
Date: 2017-08-28
modified:2025-10-26
Tags:
  • -'attack.resource-development'
  • -'attack.t1588.002'
Logsource:
  • product: windows
  • category: registry_set
Detection:
  selection:
    TargetObject|endswith: '\EulaAccepted'
  condition:selection
Falsepositives:
  -Legitimate use of SysInternals tools
  -Programs that use the same Registry Key
Level: low