kevmap

TechniquesT1588 › T1588.002

T1588.002 Tool

resource development — PRE · attack.mitre.org · JSON

1
MITRE detection strategy
1
analytics
9
Sigma rules tagged attack.t1588.002
0
KEV CVEs mapped here
<p>Adversaries may buy, steal, or download software tools that can be used during targeting. Tools can be open or closed source, free or commercial. A tool can be used for malicious purposes by an adversary, but (unlike malware) were not intended to be used for those purposes (ex: PsExec).</p><p>Adversaries may obtain tools to support their operations, including to support execution of post-compromise behaviors. Tools may also be leveraged for testing – for example, evaluating malware against commercial antivirus or endpoint detection and response (EDR) applications.</p><p>Tool acquisition may involve the procurement of commercial software licenses, including for red teaming tools such as Cobalt Strike. In addition to freely downloading or purchasing software, adversaries may steal software and/or software licenses from third-party entities (including other adversaries). Threat actors may also crack trial versions of software.</p>

KEV CVEs mapped to this technique · CTID Mappings Explorer

None. No KEV entry in the public mapping names this technique. Given that 74.7% of KEV has no mapping at all, this says more about the mapping than about the technique.

Detection strategy · ATT&CK Enterprise v19.2

Sigma rules · SigmaHQ da9bb07d64, tag attack.t1588.002

Author: Florian Roth (Nextron Systems) · 2022-03-04 (modified 2024-11-23) · logsource: product=windows category=process_creation · 24e3e58a-646b-4b50-adef-02ef935b9fc8
Detects the execution of different Windows based hacktools via their import hash (imphash) even if the files have been renamed
Techniques: T1588.002T1003
Author: Markus Neis · 2017-08-28 (modified 2025-10-26) · logsource: product=windows category=registry_set · 25ffa65d-76d8-4da5-a832-3f2b0136e133
Detects the execution of a Sysinternals Tool via the creation of the "accepteula" registry key
Techniques: T1588.002
Author: Florian Roth (Nextron Systems) · 2019-10-12 (modified 2023-08-17) · logsource: product=windows category=registry_set · 34aa0252-6039-40ff-951f-939fd6ce47d8
Detects the keyboard preload installation with a suspicious keyboard layout, e.g. Chinese, Iranian or Vietnamese layout load in user session on systems maintained by US staff only
Techniques: T1588.002
Author: Florian Roth (Nextron Systems) · 2022-04-27 (modified 2024-01-15) · logsource: product=windows category=process_creation · 37c1333a-a0db-48be-b64b-7393b2386e3b
Detects the execution of different Windows based hacktools via PE metadata (company, product, etc.) even if the files have been renamed
Techniques: T1588.002T1003
Author: Markus Neis · 2017-08-28 (modified 2024-03-13) · logsource: product=windows category=process_creation · 7cccd811-7ae9-4ebe-9afd-cb5c406b824b
Detects command lines that contain the 'accepteula' flag which could be a sign of execution of one of the Sysinternals tools
Techniques: T1588.002
Author: Nasreddine Bencherchali (Nextron Systems) · 2022-08-24 (modified 2026-06-29) · logsource: product=windows category=registry_set · 8023f872-3f1d-4301-a384-801889917ab4
Detects non-sysinternals tools setting the "accepteula" key which normally is set on sysinternals tool execution
Techniques: T1588.002
Author: Nasreddine Bencherchali (Nextron Systems) · 2022-08-24 (modified 2025-10-26) · logsource: product=windows category=registry_set · c7da8edc-49ae-45a2-9e61-9fd860e4e73d
Detects the execution of some potentially unwanted tools such as PsExec, Procdump, etc. (part of the Sysinternals suite) via the creation of the "accepteula" registry key.
Techniques: T1588.002
Author: Florian Roth (Nextron Systems) · 2020-05-28 (modified 2023-02-14) · logsource: product=windows category=process_creation · cd764533-2e07-40d6-a718-cfeec7f2da7f
Detects suspicious renamed SysInternals DebugView execution
Techniques: T1588.002
Author: Nasreddine Bencherchali (Nextron Systems) · 2022-08-24 (modified 2026-06-29) · logsource: product=windows category=registry_set · f50f3c09-557d-492d-81db-9064a8d4e211
Detects the creation of the "accepteula" key related to the Sysinternals tools being created from executables with the wrong name (e.g. a renamed Sysinternals tool)
Techniques: T1588.002

Rules tagged at the parent level (attack.t1588) 2

These target the parent technique, not this sub-technique specifically. Listed for completeness, not counted as coverage.

Author: Florian Roth (Nextron Systems), Arnim Rupp · 2017-02-19 (modified 2024-12-25) · logsource: product=windows service=application · 78bc5783-81d9-4d73-ac97-59f6db4f72a8
Detects potentially highly relevant antivirus events in the application log based on known virus signature names and malware keywords.
Techniques: T1588
Author: Florian Roth (Nextron Systems), Arnim Rupp · 2018-09-09 (modified 2026-06-29) · logsource: category=antivirus · c9a88268-0047-4824-ba6e-4d81ce0b907c
Detects an Antivirus alert in a highly relevant file path or with a relevant file name. This event must not be ignored just because the AV has blocked the malware but investigate, how it came there in the first place.
Techniques: T1588