Title:PUA - Sysinternals Tools Execution - Registry Status:test Description:Detects the execution of some potentially unwanted tools such as PsExec, Procdump, etc. (part of the Sysinternals suite) via the creation of the "accepteula" registry key. References: -https://twitter.com/Moti_B/status/1008587936735035392 Author: Nasreddine Bencherchali (Nextron Systems) Date: 2022-08-24 modified:2025-10-26 Tags:
TargetObject|endswith:
'\EulaAccepted' condition:selection Falsepositives:
-Legitimate use of SysInternals tools. Filter the legitimate paths used in your environment Level:medium