Windows AppX Execution of Sysinternals Tools (procdump/psloglist/psexec/livekd/ADExplorer)

Flags execution of common Sysinternals binaries when launched through the Windows AppX runtime.

FreeReviewedSigma · Low · v2
Product
windows
Service
appmodel-runtime
Author
Nasreddine Bencherchali (Nextron Systems) (SigmaHQ), DRL 1.1
Published
2023-01-16
Updated
2026-07-31

What it detects

This rule identifies execution of specific Sysinternals executables when they run from an AppX package context on Windows. Attackers may use Sysinternals utilities to execute actions like process inspection or remote execution while blending into non-standard application paths. It relies on Windows AppModel runtime telemetry that records process execution with matching image names for the listed tools.

Changelog

v2
  1. v2
    Candidate ingested via manual entry.2026-07-31
  2. v1
    No changelog recorded for this version.2026-07-30

Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.