Sysmon Event ID 12

Discussions on Event ID 12
Ask a question about this event

12: RegistryEvent (Object create and delete)

This is an event from Sysmon.

On this page

Registry key and value create and delete operations map to this event type, which can be useful for monitoring for changes to Registry autostart locations, or specific malware registry modifications.

Sysmon uses abbreviated versions of Registry root key names, with the following mappings:

HKEY_LOCAL_MACHINE\System\ControlSet00x	--> HKLM\System\CurrentControlSet


Free Security Log Resources by Randy

Description Fields in 12

  • Log Name
  • Source
  • Date
  • Event ID
  • Task Category
  • Level
  • Keywords
  • User
  • Computer
  • Description
  • EventType
  • UtcTime
  • ProcessGuid
  • ProcessId
  • Image
  • TargetObject

Supercharger Enterprise

Load Balancing for Windows Event Collection


Examples of 12

Registry object added or deleted:
EventType: DeleteValue
UtcTime: 2017-05-11 04:31:15.792
ProcessGuid: {a23eae89-e8bf-5913-0000-0010db9f7109}
ProcessId: 25228
Image: C:\Windows\regedit.exe
TargetObject: \REGISTRY\MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce\New Value #1


Event XML:
 <Event xmlns="">

        <Provider Name="Microsoft-Windows-Sysmon" Guid="{5770385F-C22A-43E0-BF4C-06F5698FFBD9}" />
        <TimeCreated SystemTime="2017-05-11T04:31:15.792607700Z" />
        <Correlation />
        <Execution ProcessID="3188" ThreadID="3836" />
        <Security UserID="S-1-5-18" />
        <Data Name="EventType">DeleteValue</Data>
        <Data Name="UtcTime">2017-05-11 04:31:15.792</Data>
        <Data Name="ProcessGuid">{A23EAE89-E8BF-5913-0000-0010DB9F7109}</Data>
        <Data Name="ProcessId">25228</Data>
        <Data Name="Image">C:\Windows\regedit.exe</Data>
        <Data Name="TargetObject">\REGISTRY\MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce\New Value #1</Data>


Top 10 Windows Security Events to Monitor

Free Tool for Windows Event Collection


Additional Resources