Suspicious Execution Of Renamed Sysinternals Tools - Registry

 Original Source: [Sigma source]
Title: Suspicious Execution Of Renamed Sysinternals Tools - Registry
Status: test
Description:Detects the creation of the "accepteula" key related to the Sysinternals tools being created from executables with the wrong name (e.g. a renamed Sysinternals tool)
References:
  -Internal Research
Author: Nasreddine Bencherchali (Nextron Systems)
Date: 2022-08-24
modified:2026-06-29
Tags:
  • -'attack.resource-development'
  • -'attack.t1588.002'
Logsource:
  • product: windows
  • category: registry_set
Detection:
  selection:
    TargetObject|contains:
      -'\Active Directory Explorer'
      -'\Handle'
      -'\LiveKd'
      -'\ProcDump'
      -'\Process Explorer'
      -'\PsExec'
      -'\PsLoggedon'
      -'\PsLoglist'
      -'\PsPasswd'
      -'\PsPing'
      -'\PsService'
      -'\SDelete'

    TargetObject|endswith: '\EulaAccepted'
  filter:
    Image|endswith:
      -'\ADExplorer.exe'
      -'\ADExplorer64.exe'
      -'\ADExplorer64a.exe'
      -'\handle.exe'
      -'\handle64.exe'
      -'\handle64a.exe'
      -'\livekd.exe'
      -'\livekd64.exe'
      -'\procdump.exe'
      -'\procdump64.exe'
      -'\procdump64a.exe'
      -'\procexp.exe'
      -'\procexp64.exe'
      -'\procexp64a.exe'
      -'\PsExec.exe'
      -'\PsExec64.exe'
      -'\PsExec64a.exe'
      -'\PsLoggedon.exe'
      -'\PsLoggedon64.exe'
      -'\psloglist.exe'
      -'\psloglist64.exe'
      -'\psloglist64a.exe'
      -'\pspasswd.exe'
      -'\pspasswd64.exe'
      -'\pspasswd64a.exe'
      -'\PsPing.exe'
      -'\PsPing64.exe'
      -'\PsPing64a.exe'
      -'\PsService.exe'
      -'\PsService64.exe'
      -'\PsService64a.exe'
      -'\sdelete.exe'

  condition:selection and not filter
Falsepositives:
  -Unlikely
Level: high