title: DN_0016_12_windows_sysmon_RegistryEvent description: > Registry key and value create and delete operations map to this event type, which can be useful for monitoring for changes to Registry autostart locations, or specific malware registry modifications loggingpolicy: - None references: - https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=90012 - https://github.com/Cyb3rWard0g/OSSEM/blob/master/data_dictionaries/windows/sysmon/event-12.md category: OS Logs platform: Windows type: Applications and Services Logs channel: Microsoft-Windows-Sysmon/Operational provider: Microsoft-Windows-Sysmon fields: - EventID - Computer - Hostname # redundant - EventType - UtcTime - ProcessGuid - ProcessId - Image - TargetObject sample: | - - 12 2 4 12 0 0x8000000000000000 42938 Microsoft-Windows-Sysmon/Operational atc-win-10.atc.local - DeleteKey 2019-01-30 17:05:28.023 {9683FBB1-D812-5C51-0000-0010F3871201} 10396 C:\Windows\regedit.exe HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce\New Key #1