Defender-DeviceRegistryEvents

5 ActionTypes

ActionTypeTitle
anyRegistry activity (any)
RegistryKeyCreatedRegistry key created
RegistryKeyDeletedRegistry key deleted
RegistryValueSetRegistry value set
RegistryValueDeletedRegistry value deleted

any: Registry activity (any)

#
Provider
Defender-DeviceRegistryEvents
Channel
DeviceRegistryEvents

Description

Registry activity (any)

Fields #

NameDescriptionRules
DeviceId
Timestamp
ActionType
RegistryKey
RegistryValueName
RegistryValueType
RegistryValueData1
PreviousRegistryValueData1
InitiatingProcessFileName

Common Indicators #

Field/value combinations most frequently checked by detection rules targeting this event, derived from cross-vendor predicate analysis.

FieldKindValueRulesVendors
EventTypeinRegistryKeyCreated5 ruleskusto
EventTypeinRegistryValueSet5 ruleskusto
Detailseq11 ruleelastic, kusto, splunk
ParentImageends_withcmd.exe1 rulekusto
ParentImageends_withpowershell.exe1 rulekusto
ParentImageends_withpowershell_ise.exe1 rulekusto

Detection Rules #

View all rules referencing this event →

Kusto # view in coverage

Show 2 more (5 total)

References #

RegistryKeyCreated: Registry key created

#
Provider
Defender-DeviceRegistryEvents
Channel
RegistryKeyCreated

Description

Registry key created

Fields #

NameDescription
DeviceId
Timestamp
RegistryKey
InitiatingProcessFileName

References #

RegistryKeyDeleted: Registry key deleted

#
Provider
Defender-DeviceRegistryEvents
Channel
RegistryKeyDeleted

Description

Registry key deleted

Fields #

NameDescription
DeviceId
Timestamp
RegistryKey
InitiatingProcessFileName

Common Indicators #

Field/value combinations most frequently checked by detection rules targeting this event, derived from cross-vendor predicate analysis.

FieldKindValueRulesVendors
EventTypeinRegistryKeyCreated5 ruleskusto
EventTypeinRegistryValueSet5 ruleskusto
Detailseq11 ruleelastic, kusto, splunk
ParentImageends_withcmd.exe1 rulekusto
ParentImageends_withpowershell.exe1 rulekusto
ParentImageends_withpowershell_ise.exe1 rulekusto

Detection Rules #

View all rules referencing this event →

Kusto # view in coverage

Show 2 more (5 total)

References #

RegistryValueSet: Registry value set

#
Provider
Defender-DeviceRegistryEvents
Channel
RegistryValueSet

Description

Registry value set

Fields #

NameDescriptionRules
DeviceId
Timestamp
RegistryKey
RegistryValueName1
RegistryValueData
PreviousRegistryValueData
InitiatingProcessFileName

Common Indicators #

Field/value combinations most frequently checked by detection rules targeting this event, derived from cross-vendor predicate analysis.

FieldKindValueRulesVendors
EventTypeinRegistryKeyCreated5 ruleskusto
EventTypeinRegistryValueSet5 ruleskusto
EventTypeeqRegistryValueSet4 ruleskusto
Detailseq11 ruleelastic, kusto, splunk
parent_process_nameincmd.exe1 rulekusto, splunk
parent_process_nameinpowershell.exe1 rulekusto, splunk
TargetObjectcontains\software\microsoft\windows\currentversion\policies\explorer\run1 rulekusto, sigma
GlobalPrevalencelt1001 rulekusto
GlobalPrevalenceis_null1 rulekusto
ParentImageends_withcmd.exe1 rulekusto
ParentImageends_withpowershell.exe1 rulekusto
ParentImageends_withpowershell_ise.exe1 rulekusto

Detection Rules #

View all rules referencing this event →

Kusto # view in coverage

Show 7 more (10 total)

References #

RegistryValueDeleted: Registry value deleted

#
Provider
Defender-DeviceRegistryEvents
Channel
RegistryValueDeleted

Description

Registry value deleted

Fields #

NameDescription
DeviceId
Timestamp
RegistryKey
RegistryValueName
InitiatingProcessFileName

Common Indicators #

Field/value combinations most frequently checked by detection rules targeting this event, derived from cross-vendor predicate analysis.

FieldKindValueRulesVendors
EventTypeinRegistryKeyCreated5 ruleskusto
EventTypeinRegistryValueSet5 ruleskusto
ParentImageends_withcmd.exe1 rulekusto
ParentImageends_withpowershell.exe1 rulekusto
ParentImageends_withpowershell_ise.exe1 rulekusto

Detection Rules #

View all rules referencing this event →

Kusto # view in coverage

Show 2 more (5 total)

References #