Title:
PUA - Sysinternal Tool Execution - Registry
Status:
test
Description:Detects the execution of a Sysinternals Tool via the creation of the "accepteula" registry key
References:
-https://twitter.com/Moti_B/status/1008587936735035392
Author: Markus Neis
Date: 2017-08-28
modified:2025-10-26
Tags:
- -'attack.resource-development'
- -'attack.t1588.002'
Logsource:
- product: windows
- category: registry_set
Detection:
selection:
TargetObject|endswith:
'\EulaAccepted'
condition:
selection
Falsepositives:
-Legitimate use of SysInternals tools
-Programs that use the same Registry Key
Level:
low