title: DN_0016_13_windows_sysmon_RegistryEvent description: > This Registry event type identifies Registry value modifications. The event records the value written for Registry values of type DWORD and QWORD. loggingpolicy: - None references: - https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=90013 - https://github.com/Cyb3rWard0g/OSSEM/blob/master/data_dictionaries/windows/sysmon/event-13.md platform: Windows type: Windows Log channel: Microsoft-Windows-Sysmon/Operational provider: Microsoft-Windows-Sysmon fields: - EventID - Computer - EventType - UtcTime - ProcessGuid - ProcessId - Image - TargetObject - Details sample: | - - 13 2 4 13 0 0x8000000000000000 42943 Microsoft-Windows-Sysmon/Operational atc-win-10.atc.local - SetValue 2019-01-30 17:06:11.673 {9683FBB1-D812-5C51-0000-0010F3871201} 10396 C:\Windows\regedit.exe HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce\New Value #1 C:\Program Files\Sublime Text 3\sublime_text.exe