LoFP LoFP / programs that use the same registry key

Techniques

Sample rules

PUA - Sysinternal Tool Execution - Registry

Description

Detects the execution of a Sysinternals Tool via the creation of the “accepteula” registry key

Detection logic

condition: selection
selection:
  EventType: CreateKey
  TargetObject|endswith: \EulaAccepted