PUA - Sysinternals Tools Execution - Registry

 Original Source: [Sigma source]
Title: PUA - Sysinternals Tools Execution - Registry
Status: test
Description:Detects the execution of some potentially unwanted tools such as PsExec, Procdump, etc. (part of the Sysinternals suite) via the creation of the "accepteula" registry key.
References:
  -https://twitter.com/Moti_B/status/1008587936735035392
Author: Nasreddine Bencherchali (Nextron Systems)
Date: 2022-08-24
modified:2025-10-26
Tags:
  • -'attack.resource-development'
  • -'attack.t1588.002'
Logsource:
  • product: windows
  • category: registry_set
Detection:
  selection:
    TargetObject|contains:
      -'\Active Directory Explorer'
      -'\Handle'
      -'\LiveKd'
      -'\Process Explorer'
      -'\ProcDump'
      -'\PsExec'
      -'\PsLoglist'
      -'\PsPasswd'
      -'\SDelete'
      -'\Sysinternals'

    TargetObject|endswith: '\EulaAccepted'
  condition:selection
Falsepositives:
  -Legitimate use of SysInternals tools. Filter the legitimate paths used in your environment
Level: medium