Suspicious Execution Of Renamed Sysinternals Tools - Registry
Description
Detects the creation of the "accepteula" key related to the Sysinternals tools being created from executables with the wrong name (e.g. a renamed Sysinternals tool)
Query · sigma
selection: TargetObject|contains: - \Active Directory Explorer - \Handle - \LiveKd - \ProcDump - \Process Explorer - \PsExec - \PsLoggedon - \PsLoglist - \PsPasswd - \PsPing - \PsService - \SDelete TargetObject|endswith: \EulaAccepted filter: Image|endswith: - \ADExplorer.exe - \ADExplorer64.exe - \ADExplorer64a.exe - \handle.exe - \handle64.exe - \handle64a.exe - \livekd.exe - \livekd64.exe - \procdump.exe - \procdump64.exe - \procdump64a.exe - \procexp.exe - \procexp64.exe - \procexp64a.exe - \PsExec.exe - \PsExec64.exe - \PsExec64a.exe - \PsLoggedon.exe - \PsLoggedon64.exe - \psloglist.exe - \psloglist64.exe - \psloglist64a.exe - \pspasswd.exe - \pspasswd64.exe - \pspasswd64a.exe - \PsPing.exe - \PsPing64.exe - \PsPing64a.exe - \PsService.exe - \PsService64.exe - \PsService64a.exe - \sdelete.exe condition: selection and not filter
Known false positives
- Unlikely