Microsoft-Windows-Kernel-Registry

45 events across 2 channels

Event IDTitleChannel
1Analytic
2Analytic
3Analytic
4Analytic
5Analytic
6Analytic
7Analytic
8Analytic
9Analytic
10Analytic
11Analytic
12Analytic
13Analytic
14Analytic
15Analytic
16Performance
17Performance
18Performance
19Performance
20Performance
21Performance
22Performance
23Performance
24Performance
25Performance
26Performance
27Performance
28Performance
29Performance
30Performance
31Performance
32Performance
33Performance
34Performance
35Performance
36Performance
37Performance
38Performance
39Performance
40Performance
41Performance
42Performance
43Performance
44Performance
45Performance

Event ID 1 —

Provider
Microsoft-Windows-Kernel-Registry
Channel
Analytic

Fields

NameDescription
BaseObject
KeyObject
Status
Disposition
BaseName
RelativeName

Event ID 2 —

Provider
Microsoft-Windows-Kernel-Registry
Channel
Analytic

Fields

NameDescription
BaseObject
KeyObject
Status
Disposition
BaseName
RelativeName

Event ID 3 —

Provider
Microsoft-Windows-Kernel-Registry
Channel
Analytic

Fields

NameDescription
KeyObject
Status
KeyName

Event ID 4 —

Provider
Microsoft-Windows-Kernel-Registry
Channel
Analytic

Fields

NameDescription
KeyObject
Status
InfoClass
DataSize
KeyName
CapturedDataSize
CapturedData

Event ID 5 —

Provider
Microsoft-Windows-Kernel-Registry
Channel
Analytic

Fields

NameDescription
KeyObject
Status
Type
DataSize
KeyName
ValueName
CapturedDataSize
CapturedData
PreviousDataType
PreviousDataSize
PreviousDataCapturedSize
PreviousData

Event ID 6 —

Provider
Microsoft-Windows-Kernel-Registry
Channel
Analytic

Fields

NameDescription
KeyObject
Status
KeyName
ValueName

Event ID 7 —

Provider
Microsoft-Windows-Kernel-Registry
Channel
Analytic

Fields

NameDescription
KeyObject
Status
InfoClass
DataSize
KeyName
ValueName
CapturedDataSize
CapturedData

Event ID 8 —

Provider
Microsoft-Windows-Kernel-Registry
Channel
Analytic

Fields

NameDescription
KeyObject
Status
Index
InfoClass
DataSize
KeyName
CapturedDataSize
CapturedData

Event ID 9 —

Provider
Microsoft-Windows-Kernel-Registry
Channel
Analytic

Fields

NameDescription
KeyObject
Status
Index
InfoClass
DataSize
KeyName
CapturedDataSize
CapturedData

Event ID 10 —

Provider
Microsoft-Windows-Kernel-Registry
Channel
Analytic

Fields

NameDescription
KeyObject
Status
EntryCount
DataSize
KeyName

Event ID 11 —

Provider
Microsoft-Windows-Kernel-Registry
Channel
Analytic

Fields

NameDescription
KeyObject
Status
InfoClass
DataSize
KeyName
CapturedDataSize
CapturedData

Event ID 12 —

Provider
Microsoft-Windows-Kernel-Registry
Channel
Analytic

Fields

NameDescription
KeyObject
Status
KeyName

Event ID 13 —

Provider
Microsoft-Windows-Kernel-Registry
Channel
Analytic

Fields

NameDescription
KeyObject
Status
KeyName

Event ID 14 —

Provider
Microsoft-Windows-Kernel-Registry
Channel
Analytic

Fields

NameDescription
KeyObject
Status
KeyName

Event ID 15 —

Provider
Microsoft-Windows-Kernel-Registry
Channel
Analytic

Fields

NameDescription
KeyObject
Status
KeyName

Event ID 16 —

Provider
Microsoft-Windows-Kernel-Registry
Channel
Performance

Event ID 17 —

Provider
Microsoft-Windows-Kernel-Registry
Channel
Performance

Fields

NameDescription
HiveFilePath
FileSize

Event ID 18 —

Provider
Microsoft-Windows-Kernel-Registry
Channel
Performance

Fields

NameDescription
TotalEntrySize
BytesRecovered

Event ID 19 —

Provider
Microsoft-Windows-Kernel-Registry
Channel
Performance

Fields

NameDescription
StatusCode

Event ID 20 —

Provider
Microsoft-Windows-Kernel-Registry
Channel
Performance

Fields

NameDescription
HiveFilePath
HiveMountPoint

Event ID 21 —

Provider
Microsoft-Windows-Kernel-Registry
Channel
Performance

Fields

NameDescription
StatusCode

Event ID 22 —

Provider
Microsoft-Windows-Kernel-Registry
Channel
Performance

Fields

NameDescription
HiveFilePath
HiveMountPoint
FlushFlags

Event ID 23 —

Provider
Microsoft-Windows-Kernel-Registry
Channel
Performance

Event ID 24 —

Provider
Microsoft-Windows-Kernel-Registry
Channel
Performance

Fields

NameDescription
BytesGathered

Event ID 25 —

Provider
Microsoft-Windows-Kernel-Registry
Channel
Performance

Fields

NameDescription
BytesGathered

Event ID 26 —

Provider
Microsoft-Windows-Kernel-Registry
Channel
Performance

Fields

NameDescription
WritesIssued
BytesWritten

Event ID 27 —

Provider
Microsoft-Windows-Kernel-Registry
Channel
Performance

Fields

NameDescription
WritesIssued
BytesWritten

Event ID 28 —

Provider
Microsoft-Windows-Kernel-Registry
Channel
Performance

Event ID 29 —

Provider
Microsoft-Windows-Kernel-Registry
Channel
Performance

Event ID 30 —

Provider
Microsoft-Windows-Kernel-Registry
Channel
Performance

Event ID 31 —

Provider
Microsoft-Windows-Kernel-Registry
Channel
Performance

Fields

NameDescription
StatusCode

Event ID 32 —

Provider
Microsoft-Windows-Kernel-Registry
Channel
Performance

Event ID 33 —

Provider
Microsoft-Windows-Kernel-Registry
Channel
Performance

Event ID 34 —

Provider
Microsoft-Windows-Kernel-Registry
Channel
Performance

Event ID 35 —

Provider
Microsoft-Windows-Kernel-Registry
Channel
Performance

Event ID 36 —

Provider
Microsoft-Windows-Kernel-Registry
Channel
Performance

Event ID 37 —

Provider
Microsoft-Windows-Kernel-Registry
Channel
Performance

Fields

NameDescription
SourceFile
Flags

Event ID 38 —

Provider
Microsoft-Windows-Kernel-Registry
Channel
Performance

Fields

NameDescription
StatusCode

Event ID 39 —

Provider
Microsoft-Windows-Kernel-Registry
Channel
Performance

Fields

NameDescription
SourceFile
Flags

Event ID 40 —

Provider
Microsoft-Windows-Kernel-Registry
Channel
Performance

Fields

NameDescription
StatusCode

Event ID 41 —

Provider
Microsoft-Windows-Kernel-Registry
Channel
Performance

Fields

NameDescription
SourceKeyPath

Event ID 42 —

Provider
Microsoft-Windows-Kernel-Registry
Channel
Performance

Event ID 43 —

Provider
Microsoft-Windows-Kernel-Registry
Channel
Performance

Event ID 44 —

Provider
Microsoft-Windows-Kernel-Registry
Channel
Performance

Event ID 45 —

Provider
Microsoft-Windows-Kernel-Registry
Channel
Performance

Fields

NameDescription
StatusCode