{"id":"T1588.002","name":"Tool","url":"https://attack.mitre.org/techniques/T1588/002","tactics":["resource-development"],"platforms":["PRE"],"live":true,"revoked":false,"deprecated":false,"revoked_by":null,"detection_strategies":[{"id":"DET0852","stix_id":"x-mitre-detection-strategy--cb821d3c-ede3-43a4-915b-f779b04318f6","name":"Detection of Tool","url":"https://attack.mitre.org/detectionstrategies/DET0852","analytics":[{"id":"AN1984","stix_id":"x-mitre-analytic--6f7fa682-fd50-4de4-add3-cbaa3c127b70","name":"Analytic 1984","description":"Monitor for contextual data about a malicious payload, such as compilation times, file hashes, as well as watermarks or other identifiable configuration information. In some cases, malware repositories can also be used to identify features of tool use associated with an adversary, such as watermarks in [Cobalt Strike](https://attack.mitre.org/software/S0154) payloads.(Citation: Analyzing CS Dec 2020)\nMuch of this activity will take place outside the visibility of the target organization, making detection of this behavior difficult. Detection efforts may be focused on post-compromise phases of the adversary lifecycle.","url":"https://attack.mitre.org/detectionstrategies/DET0852#AN1984","platforms":["PRE"],"log_source_references":[{"name":"Malware Repository","channel":"None","data_component":"DC0003","data_component_name":"Malware Metadata","log_source_slug":"malware-repository"}],"mutable_elements":[],"live":true,"detection_strategies":["DET0852"],"techniques":["T1588.002"]}],"live":true,"version":"1.0","techniques":["T1588.002"]}],"sigma_rules":[{"id":"24e3e58a-646b-4b50-adef-02ef935b9fc8","title":"Hacktool Execution - Imphash","author":"Florian Roth (Nextron Systems)","status":"test","level":"critical","date":"2022-03-04","modified":"2024-11-23","description":"Detects the execution of different Windows based hacktools via their import hash (imphash) even if the files have been renamed","references":["Internal Research"],"logsource":{"product":"windows","category":"process_creation"},"tags":["attack.credential-access","attack.resource-development","attack.t1588.002","attack.t1003"],"path":"rules/windows/process_creation/proc_creation_win_hktl_execution_via_imphashes.yml","techniques":["T1588.002","T1003"],"cves":[]},{"id":"25ffa65d-76d8-4da5-a832-3f2b0136e133","title":"PUA - Sysinternal Tool Execution - Registry","author":"Markus Neis","status":"test","level":"low","date":"2017-08-28","modified":"2025-10-26","description":"Detects the execution of a Sysinternals Tool via the creation of the \"accepteula\" registry key","references":["https://twitter.com/Moti_B/status/1008587936735035392"],"logsource":{"product":"windows","category":"registry_set"},"tags":["attack.resource-development","attack.t1588.002"],"path":"rules/windows/registry/registry_set/registry_set_pua_sysinternals_execution_via_eula.yml","techniques":["T1588.002"],"cves":[]},{"id":"34aa0252-6039-40ff-951f-939fd6ce47d8","title":"Suspicious Keyboard Layout Load","author":"Florian Roth (Nextron Systems)","status":"test","level":"medium","date":"2019-10-12","modified":"2023-08-17","description":"Detects the keyboard preload installation with a suspicious keyboard layout, e.g. Chinese, Iranian or Vietnamese layout load in user session on systems maintained by US staff only","references":["https://renenyffenegger.ch/notes/Windows/registry/tree/HKEY_CURRENT_USER/Keyboard-Layout/Preload/index","https://github.com/SwiftOnSecurity/sysmon-config/pull/92/files"],"logsource":{"product":"windows","category":"registry_set"},"tags":["attack.resource-development","attack.t1588.002"],"path":"rules/windows/registry/registry_set/registry_set_susp_keyboard_layout_load.yml","techniques":["T1588.002"],"cves":[]},{"id":"37c1333a-a0db-48be-b64b-7393b2386e3b","title":"Hacktool Execution - PE Metadata","author":"Florian Roth (Nextron Systems)","status":"test","level":"high","date":"2022-04-27","modified":"2024-01-15","description":"Detects the execution of different Windows based hacktools via PE metadata (company, product, etc.) even if the files have been renamed","references":["https://github.com/cube0x0","https://www.virustotal.com/gui/search/metadata%253ACube0x0/files"],"logsource":{"product":"windows","category":"process_creation"},"tags":["attack.credential-access","attack.resource-development","attack.t1588.002","attack.t1003"],"path":"rules/windows/process_creation/proc_creation_win_hktl_execution_via_pe_metadata.yml","techniques":["T1588.002","T1003"],"cves":[]},{"id":"7cccd811-7ae9-4ebe-9afd-cb5c406b824b","title":"Potential Execution of Sysinternals Tools","author":"Markus Neis","status":"test","level":"low","date":"2017-08-28","modified":"2024-03-13","description":"Detects command lines that contain the 'accepteula' flag which could be a sign of execution of one of the Sysinternals tools","references":["https://twitter.com/Moti_B/status/1008587936735035392"],"logsource":{"product":"windows","category":"process_creation"},"tags":["attack.resource-development","attack.t1588.002"],"path":"rules/windows/process_creation/proc_creation_win_sysinternals_eula_accepted.yml","techniques":["T1588.002"],"cves":[]},{"id":"8023f872-3f1d-4301-a384-801889917ab4","title":"Usage of Renamed Sysinternals Tools - RegistrySet","author":"Nasreddine Bencherchali (Nextron Systems)","status":"test","level":"high","date":"2022-08-24","modified":"2026-06-29","description":"Detects non-sysinternals tools setting the \"accepteula\" key which normally is set on sysinternals tool execution","references":["Internal Research"],"logsource":{"product":"windows","category":"registry_set"},"tags":["attack.resource-development","attack.t1588.002"],"path":"rules/windows/registry/registry_set/registry_set_renamed_sysinternals_eula_accepted.yml","techniques":["T1588.002"],"cves":[]},{"id":"c7da8edc-49ae-45a2-9e61-9fd860e4e73d","title":"PUA - Sysinternals Tools Execution - Registry","author":"Nasreddine Bencherchali (Nextron Systems)","status":"test","level":"medium","date":"2022-08-24","modified":"2025-10-26","description":"Detects the execution of some potentially unwanted tools such as PsExec, Procdump, etc. (part of the Sysinternals suite) via the creation of the \"accepteula\" registry key.","references":["https://twitter.com/Moti_B/status/1008587936735035392"],"logsource":{"product":"windows","category":"registry_set"},"tags":["attack.resource-development","attack.t1588.002"],"path":"rules/windows/registry/registry_set/registry_set_pua_sysinternals_susp_execution_via_eula.yml","techniques":["T1588.002"],"cves":[]},{"id":"cd764533-2e07-40d6-a718-cfeec7f2da7f","title":"Renamed SysInternals DebugView Execution","author":"Florian Roth (Nextron Systems)","status":"test","level":"high","date":"2020-05-28","modified":"2023-02-14","description":"Detects suspicious renamed SysInternals DebugView execution","references":["https://www.epicturla.com/blog/sysinturla"],"logsource":{"product":"windows","category":"process_creation"},"tags":["attack.resource-development","attack.t1588.002"],"path":"rules/windows/process_creation/proc_creation_win_renamed_sysinternals_debugview.yml","techniques":["T1588.002"],"cves":[]},{"id":"f50f3c09-557d-492d-81db-9064a8d4e211","title":"Suspicious Execution Of Renamed Sysinternals Tools - Registry","author":"Nasreddine Bencherchali (Nextron Systems)","status":"test","level":"high","date":"2022-08-24","modified":"2026-06-29","description":"Detects the creation of the \"accepteula\" key related to the Sysinternals tools being created from executables with the wrong name (e.g. a renamed Sysinternals tool)","references":["Internal Research"],"logsource":{"product":"windows","category":"registry_set"},"tags":["attack.resource-development","attack.t1588.002"],"path":"rules/windows/registry/registry_set/registry_set_pua_sysinternals_renamed_execution_via_eula.yml","techniques":["T1588.002"],"cves":[]}],"kev_cves":[],"_built":"2026-08-24 19:45 UTC","_attack_version":"19.2","_sigma_commit":"da9bb07d642a2826e89702445d32c795209ec108"}