title: Usage of Renamed Sysinternals Tools - RegistrySet id: 8023f872-3f1d-4301-a384-801889917ab4 related: - id: 25ffa65d-76d8-4da5-a832-3f2b0136e133 type: derived - id: f50f3c09-557d-492d-81db-9064a8d4e211 type: similar status: test description: Detects non-sysinternals tools setting the "accepteula" key which normally is set on sysinternals tool execution references: - Internal Research author: Nasreddine Bencherchali (Nextron Systems) date: 2022-08-24 modified: 2026-06-29 tags: - attack.resource-development - attack.t1588.002 logsource: product: windows category: registry_set detection: selection: TargetObject|contains: - '\PsExec' - '\ProcDump' - '\Handle' - '\LiveKd' - '\Process Explorer' - '\PsLoglist' - '\PsPasswd' - '\Active Directory Explorer' TargetObject|endswith: '\EulaAccepted' filter_main_image_names: Image|endswith: - '\PsExec.exe' - '\PsExec64.exe' - '\PsExec64a.exe' - '\procdump.exe' - '\procdump64.exe' - '\procdump64a.exe' - '\handle.exe' - '\handle64.exe' - '\handle64a.exe' - '\livekd.exe' - '\livekd64.exe' - '\procexp.exe' - '\procexp64.exe' - '\procexp64a.exe' - '\psloglist.exe' - '\psloglist64.exe' - '\psloglist64a.exe' - '\pspasswd.exe' - '\pspasswd64.exe' - '\pspasswd64a.exe' - '\ADExplorer.exe' - '\ADExplorer64.exe' - '\ADExplorer64a.exe' filter_optional_null: Image: null # Race condition with some logging tools condition: selection and not 1 of filter_main_* and not 1 of filter_optional_* falsepositives: - Unlikely level: high