Suspicious Use of PsLogList (via process_creation)
This rule detects use of the PsLogList utility to dump event log to extract admin accounts and perform account discovery or delete events logs
SigmamediumWindowsv1
sigma
suspicious-use-of-psloglist-via-process-creation
title: Suspicious Use of PsLogList (via process_creation)
id: 45e656df-856f-5080-ad3a-21744e78d3a9
status: stable
description: This rule detects use of the PsLogList utility to dump event log to extract admin accounts and perform account discovery or delete events logs
references:
- https://attack.mitre.org/techniques/T1087/002/
- https://attack.mitre.org/techniques/T1087/001/
- https://attack.mitre.org/techniques/T1087/
- https://research.nccgroup.com/2021/01/12/abusing-cloud-services-to-fly-under-the-radar/
- https://www.cybereason.com/blog/deadringer-exposing-chinese-threat-actors-targeting-major-telcos
- https://github.com/3CORESec/MAL-CL/tree/master/Descriptors/Sysinternals/PsLogList
- https://twitter.com/EricaZelic/status/1614075109827874817
author: Huntrule Team
date: 2026-05-05
tags:
- attack.discovery
- attack.t1087
- attack.t1087.001
- attack.t1087.002
logsource:
category: process_creation
product: windows
detection:
selection_img:
- OriginalFileName: 'psloglist.exe'
- Image|endswith:
- '\psloglist.exe'
- '\psloglist64.exe'
- '\psloglist64a.exe'
selection_cli_eventlog:
CommandLine|contains:
- ' security'
- ' application'
- ' system'
selection_cli_flags:
CommandLine|contains|windash:
- ' -d'
- ' -x'
- ' -s'
- ' -c'
- ' -g'
condition: all of selection_*
falsepositives:
- Unknown
level: medium
Known false positives
- Unknown
Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.