Windows Registry Set: Sysinternals EULA Accepted Key for PUA Tool Execution
Flags Sysinternals-related registry EULA acceptance writes tied to PsExec/ProcDump/Process Explorer and other tools.
- Product
- windows
- Category
- registry_set
- Author
- Nasreddine Bencherchali (Nextron Systems) (SigmaHQ), DRL 1.1
- Published
- 2022-08-24
- Updated
- 2026-07-30
ATT&CK techniques
Resource DevRecon
Resource Dev
Initial Access
Execution
Persistence
Priv Esc
Defense Evasion
Cred Access
Discovery
Lateral Movement
Collection
C2
Exfiltration
Impact
What it detects
This rule flags registry writes where the TargetObject ends with \EulaAccepted for specific Sysinternals-related tool paths (including PsExec, ProcDump, Process Explorer, and others). Attackers and tool users may use these keys as part of executing or deploying potentially unwanted utilities from the Sysinternals suite, which can enable discovery, credential or process access, or system manipulation. It relies on Windows registry_set telemetry capturing the TargetObject path and matching the specified tool names and the EULA acceptance suffix.
Reporting behind it
Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.
title: "Windows Registry Set: Sysinternals EULA Accepted Key for PUA Tool Execution"
id: b7357784-7424-4022-a3d3-380f36e2217a
related:
- id: 25ffa65d-76d8-4da5-a832-3f2b0136e133
type: derived
- id: 9841b233-8df8-4ad7-9133-b0b4402a9014
type: obsolete
- id: c7da8edc-49ae-45a2-9e61-9fd860e4e73d
type: derived
status: test
description: This rule flags registry writes where the TargetObject ends with \EulaAccepted for specific Sysinternals-related tool paths (including PsExec, ProcDump, Process Explorer, and others). Attackers and tool users may use these keys as part of executing or deploying potentially unwanted utilities from the Sysinternals suite, which can enable discovery, credential or process access, or system manipulation. It relies on Windows registry_set telemetry capturing the TargetObject path and matching the specified tool names and the EULA acceptance suffix.
references:
- https://twitter.com/Moti_B/status/1008587936735035392
- https://github.com/SigmaHQ/sigma/blob/master/rules/windows/registry/registry_set/registry_set_pua_sysinternals_susp_execution_via_eula.yml
author: Nasreddine Bencherchali (Nextron Systems), Huntrule Team
date: 2022-08-24
modified: 2025-10-26
tags:
- attack.resource-development
- attack.t1588.002
logsource:
product: windows
category: registry_set
detection:
selection:
TargetObject|contains:
- \Active Directory Explorer
- \Handle
- \LiveKd
- \Process Explorer
- \ProcDump
- \PsExec
- \PsLoglist
- \PsPasswd
- \SDelete
- \Sysinternals
TargetObject|endswith: \EulaAccepted
condition: selection
falsepositives:
- Legitimate use of SysInternals tools. Filter the legitimate paths used in your environment
level: medium
regression_tests_path: regression_data/rules/windows/registry/registry_set/registry_set_pua_sysinternals_susp_execution_via_eula/info.yml
license: DRL-1.1