Defender-DeviceRegistryEvents

5 events across 5 channels

Event IDTitleChannel
9005000Registry activity (any)DeviceRegistryEvents
9005001Registry key createdRegistryKeyCreated
9005002Registry key deletedRegistryKeyDeleted
9005003Registry value setRegistryValueSet
9005004Registry value deletedRegistryValueDeleted

Event ID 9005000 — Registry activity (any)

#
Provider
Defender-DeviceRegistryEvents
Channel
DeviceRegistryEvents

Description

Registry activity (any)

Fields #

NameDescription
DeviceId
Timestamp
ActionType
RegistryKey
RegistryValueName
RegistryValueType
RegistryValueData
PreviousRegistryValueData
InitiatingProcessFileName

Detection Patterns #

References #

Event ID 9005001 — Registry key created

Provider
Defender-DeviceRegistryEvents
Channel
RegistryKeyCreated

Description

Registry key created

Fields #

NameDescription
DeviceId
Timestamp
RegistryKey
InitiatingProcessFileName

References #

Event ID 9005002 — Registry key deleted

#
Provider
Defender-DeviceRegistryEvents
Channel
RegistryKeyDeleted

Description

Registry key deleted

Fields #

NameDescription
DeviceId
Timestamp
RegistryKey
InitiatingProcessFileName

Detection Patterns #

References #

Event ID 9005003 — Registry value set

#
Provider
Defender-DeviceRegistryEvents
Channel
RegistryValueSet

Description

Registry value set

Fields #

NameDescription
DeviceId
Timestamp
RegistryKey
RegistryValueName
RegistryValueData
PreviousRegistryValueData
InitiatingProcessFileName

Detection Patterns #

References #

Event ID 9005004 — Registry value deleted

#
Provider
Defender-DeviceRegistryEvents
Channel
RegistryValueDeleted

Description

Registry value deleted

Fields #

NameDescription
DeviceId
Timestamp
RegistryKey
RegistryValueName
InitiatingProcessFileName

Detection Patterns #

References #