Windows Registry Set: Sysinternals EULA Accepted Key for PUA Tool Execution

Flags Sysinternals-related registry EULA acceptance writes tied to PsExec/ProcDump/Process Explorer and other tools.

FreeReviewedSigma · Medium · v1
Product
windows
Category
registry_set
Author
Nasreddine Bencherchali (Nextron Systems) (SigmaHQ), DRL 1.1
Published
2022-08-24
Updated
2026-07-30

ATT&CK techniques

Resource Dev
  1. Recon

  2. Resource Dev

  3. Initial Access

  4. Execution

  5. Persistence

  6. Priv Esc

  7. Defense Evasion

  8. Cred Access

  9. Discovery

  10. Lateral Movement

  11. Collection

  12. C2

  13. Exfiltration

  14. Impact

What it detects

This rule flags registry writes where the TargetObject ends with \EulaAccepted for specific Sysinternals-related tool paths (including PsExec, ProcDump, Process Explorer, and others). Attackers and tool users may use these keys as part of executing or deploying potentially unwanted utilities from the Sysinternals suite, which can enable discovery, credential or process access, or system manipulation. It relies on Windows registry_set telemetry capturing the TargetObject path and matching the specified tool names and the EULA acceptance suffix.

Related detections9 linkedT1588.002 — drag to rearrange
Malicious Viper C2 Installation via f8x One-Liner Setup Script (via process_creation)
Windows RegistrySet: EulaAccepted set for renamed Sysinternals tools
Windows Registry: Sysinternals Renamed Tool Execution Indicator via EulaAccepted Key
Windows Hacktool Execution via PE Metadata Company Field
Windows Hacktool Execution Flagged by Imphash in Process Creation
Windows: Renamed Sysinternals DebugView Process Execution
Windows Registry: Suspicious Keyboard Layout Preload in User Session
Windows Registry Key Created: Sysinternals EULA Acceptance
Windows: Command-line execution using Sysinternals -accepteula flag
Windows Registry Set: Sysinternals EULA Accepted Key for PUA Tool Execution
Pivot detection · T1588.002 · 9 related

Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.