Defender-DeviceRegistryEvents › Event 9005000

Event ID 9005000 — Registry activity (any)

Provider
Defender-DeviceRegistryEvents
Channel
DeviceRegistryEvents

Description

Registry activity (any)

Fields #

NameDescription
DeviceId
Timestamp
ActionType
RegistryKey
RegistryValueName
RegistryValueType
RegistryValueData
PreviousRegistryValueData
InitiatingProcessFileName

Detection Patterns #

References #