Windows RegistrySet: EulaAccepted set for renamed Sysinternals tools
Flags Windows registry writes to \EulaAccepted for Sysinternals-related objects when performed by non-matching executables.
FreeUnreviewedSigmahighv1
windows-registryset-eulaaccepted-set-for-renamed-sysinternals-tools-8023f872
title: "Windows RegistrySet: EulaAccepted set for renamed Sysinternals tools"
id: 3e6b7617-0113-4a1c-8fb8-9249ca818b25
related:
- id: 25ffa65d-76d8-4da5-a832-3f2b0136e133
type: derived
- id: f50f3c09-557d-492d-81db-9064a8d4e211
type: similar
- id: 8023f872-3f1d-4301-a384-801889917ab4
type: derived
status: test
description: This rule identifies registry writes where the TargetObject contains specific Sysinternals-related path patterns and ends with \EulaAccepted, indicating the EULA acceptance flag was set. It then excludes events where the setting is performed by the expected Sysinternals executable image names. Attackers may use renamed or proxy binaries to blend in while still setting the same EULA acceptance registry value, so the detection relies on Windows RegistrySet telemetry capturing TargetObject and the writing process Image.
references:
- Internal Research
- https://github.com/SigmaHQ/sigma/blob/master/rules/windows/registry/registry_set/registry_set_renamed_sysinternals_eula_accepted.yml
author: Nasreddine Bencherchali (Nextron Systems), Huntrule Team
date: 2022-08-24
modified: 2026-06-29
tags:
- attack.resource-development
- attack.t1588.002
logsource:
product: windows
category: registry_set
detection:
selection:
TargetObject|contains:
- \PsExec
- \ProcDump
- \Handle
- \LiveKd
- \Process Explorer
- \PsLoglist
- \PsPasswd
- \Active Directory Explorer
TargetObject|endswith: \EulaAccepted
filter_main_image_names:
Image|endswith:
- \PsExec.exe
- \PsExec64.exe
- \PsExec64a.exe
- \procdump.exe
- \procdump64.exe
- \procdump64a.exe
- \handle.exe
- \handle64.exe
- \handle64a.exe
- \livekd.exe
- \livekd64.exe
- \procexp.exe
- \procexp64.exe
- \procexp64a.exe
- \psloglist.exe
- \psloglist64.exe
- \psloglist64a.exe
- \pspasswd.exe
- \pspasswd64.exe
- \pspasswd64a.exe
- \ADExplorer.exe
- \ADExplorer64.exe
- \ADExplorer64a.exe
filter_optional_null:
Image: null
condition: selection and not 1 of filter_main_* and not 1 of filter_optional_*
falsepositives:
- Unlikely
level: high
license: DRL-1.1
What it detects
This rule identifies registry writes where the TargetObject contains specific Sysinternals-related path patterns and ends with \EulaAccepted, indicating the EULA acceptance flag was set. It then excludes events where the setting is performed by the expected Sysinternals executable image names. Attackers may use renamed or proxy binaries to blend in while still setting the same EULA acceptance registry value, so the detection relies on Windows RegistrySet telemetry capturing TargetObject and the writing process Image.
Known false positives
- Unlikely
Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.