title: DN_0059_4657_registry_value_was_modified description: > This event generates when a registry key value was modified. It doesn't generate when a registry key was modified. This event generates only if "Set Value" auditing is set in registry key’s SACL loggingpolicy: - LP_0103_windows_audit_registry references: - https://github.com/MicrosoftDocs/windows-itpro-docs/blob/master/windows/security/threat-protection/auditing/event-4657.md category: OS Logs platform: Windows type: Windows Log channel: Security provider: Microsoft-Windows-Security-Auditing fields: - EventID - Computer - Hostname # redundant - SubjectUserSid - SubjectUserName - SubjectDomainName - SubjectLogonId - ObjectName - ObjectValueName - HandleId - OperationType - OldValueType - OldValue - NewValueType - NewValue - ProcessId - ProcessName sample: | - - 4657 0 0 12801 0 0x8020000000000000 744725 Security DC01.contoso.local - S-1-5-21-3457937927-2839227994-823803824-1104 dadmin CONTOSO 0x364eb \\REGISTRY\\MACHINE Name\_New 0x54 %%1905 %%1873 %%1873 Andrei 0xce4 C:\\Windows\\regedit.exe