Defender-DeviceRegistryEvents

6 ActionTypes

ActionTypeTitle
anyRegistry activity (any)
RegistryKeyCreatedRegistry key created
RegistryKeyDeletedRegistry key deleted
RegistryValueSetRegistry value set
RegistryValueDeletedRegistry value deleted
RegistryKeyRenamedRegistry key renamed

any: Registry activity (any)

#
Table
DeviceRegistryEvents

Description

Registry activity (any)

Fields #

NameDescription
DeviceId
Timestamp
ActionType
RegistryKey
RegistryValueName
RegistryValueType
RegistryValueData
PreviousRegistryValueData
InitiatingProcessFileName

References #

RegistryKeyCreated: Registry key created

#
Table
DeviceRegistryEvents

Description

Registry key created

Fields #

NameDescription
DeviceId
Timestamp
RegistryKey
InitiatingProcessFileName

References #

RegistryKeyDeleted: Registry key deleted

#
Table
DeviceRegistryEvents

Description

Registry key deleted

Fields #

NameDescription
DeviceId
Timestamp
RegistryKey
InitiatingProcessFileName

Common Indicators #

Field/value combinations most frequently checked by detection rules targeting this event, derived from cross-vendor predicate analysis.

FieldKindValueRulesVendors
EventTypeinRegistryKeyCreated5 ruleskusto
EventTypeinRegistryValueSet5 ruleskusto
Detailseq11 ruleelastic, kusto, splunk
ParentImageends_withcmd.exe1 rulekusto
ParentImageends_withpowershell.exe1 rulekusto
ParentImageends_withpowershell_ise.exe1 rulekusto
TargetObjectcontainssoftware\\classes\\ms-settings\\shell\\open\\command1 rulekusto

Detection Rules #

View all rules referencing this event →

Kusto #

Show 2 more (5 total)

References #

RegistryValueSet: Registry value set

#
Table
DeviceRegistryEvents

Description

Registry value set

Fields #

NameDescriptionRules
DeviceId
Timestamp
RegistryKey
RegistryValueName1 detection rule
RegistryValueData
PreviousRegistryValueData
InitiatingProcessFileName

Common Indicators #

Field/value combinations most frequently checked by detection rules targeting this event, derived from cross-vendor predicate analysis.

FieldKindValueRulesVendors
EventTypeeqRegistryValueSet4 ruleskusto
EventTypeinRegistryKeyCreated5 ruleskusto
EventTypeinRegistryValueSet5 ruleskusto
Detailseq11 ruleelastic, kusto, splunk
GlobalPrevalenceis_null1 rulekusto
GlobalPrevalencelt1001 rulekusto
ParentImageends_withcmd.exe1 rulekusto
ParentImageends_withpowershell.exe1 rulekusto
ParentImageends_withpowershell_ise.exe1 rulekusto
TargetObjectcontains\software\microsoft\windows\currentversion\policies\explorer\run1 rulekusto, sigma
TargetObjectcontainssoftware\\classes\\ms-settings\\shell\\open\\command1 rulekusto
parent_process_nameincmd.exe1 ruleelastic, kusto, splunk
parent_process_nameinpowershell.exe1 ruleelastic, kusto, splunk

Detection Rules #

View all rules referencing this event →

Kusto #

Show 7 more (10 total)

References #

RegistryValueDeleted: Registry value deleted

#
Table
DeviceRegistryEvents

Description

Registry value deleted

Fields #

NameDescription
DeviceId
Timestamp
RegistryKey
RegistryValueName
InitiatingProcessFileName

Common Indicators #

Field/value combinations most frequently checked by detection rules targeting this event, derived from cross-vendor predicate analysis.

FieldKindValueRulesVendors
EventTypeinRegistryKeyCreated5 ruleskusto
EventTypeinRegistryValueSet5 ruleskusto
Detailseq11 ruleelastic, kusto, splunk
ParentImageends_withcmd.exe1 rulekusto
ParentImageends_withpowershell.exe1 rulekusto
ParentImageends_withpowershell_ise.exe1 rulekusto
TargetObjectcontainssoftware\\classes\\ms-settings\\shell\\open\\command1 rulekusto

Detection Rules #

View all rules referencing this event →

Kusto #

Show 2 more (5 total)

References #

RegistryKeyRenamed: Registry key renamed

#
Table
DeviceRegistryEvents

Description

Registry key renamed. Sysmon-14 RegistryEvent (Key and Value Rename) is the one-to-one Windows native equivalent. ASIM RegistryEvent parsers map this AT consistently across MDE, Sysmon, Carbon Black, and SentinelOne sources.

Fields #

NameDescription
DeviceId
Timestamp
RegistryKey
PreviousRegistryKey
InitiatingProcessFileName

Common Indicators #

Field/value combinations most frequently checked by detection rules targeting this event, derived from cross-vendor predicate analysis.

FieldKindValueRulesVendors
EventTypeinRegistryKeyCreated5 ruleskusto
EventTypeinRegistryValueSet5 ruleskusto
ParentImageends_withcmd.exe1 rulekusto
ParentImageends_withpowershell.exe1 rulekusto
ParentImageends_withpowershell_ise.exe1 rulekusto
TargetObjectcontainssoftware\\classes\\ms-settings\\shell\\open\\command1 rulekusto

Detection Rules #

View all rules referencing this event →

Kusto #

Show 2 more (5 total)

References #