Skip to main content

Registry value

3actions
3reasons
1sources
Livestatus

A value in the Windows registry that auditing is turned on for.

Identified by: sparklogs.config_change.target, which carries a name.

ActionReported byWhat that reason says
createdwin_registry_value_created on Windows Security event logAn audited registry value was created. These events appear only where a SACL and the registry audit subcategory are aimed at that object.
deletedwin_registry_value_deleted on Windows Security event logAn audited registry value was deleted. These events appear only where a SACL and the registry audit subcategory are aimed at that object.
updatedwin_registry_value_changed on Windows Security event logAn audited registry value was modified. These events appear only where a SACL and the registry audit subcategory are aimed at that object.

Example

A registry value was modified.

channel: Security
provider_name: Microsoft-Windows-Security-Auditing
event_id: 4657
event_data.ObjectName: \REGISTRY\MACHINE\SOFTWARE\Example
event_data.ObjectValueName: Run
event_data.OperationType: %%1905
event_data.ProcessName: C:\Windows\regedit.exe
event_data.SubjectUserName: ExampleAdmin

SparkLogs: win_registry_value_changed, Warning, win_registry_value_changed: NOTABLE: A registry value was modified. | operation_meaning=value_modified