Sysmon Event ID 12


12: RegistryEvent (Object create and delete)

This is an event from Sysmon.

On this page

Registry key and value create and delete operations map to this event type, which can be useful for monitoring for changes to Registry autostart locations, or specific malware registry modifications.

Sysmon uses abbreviated versions of Registry root key names, with the following mappings:

HKEY_LOCAL_MACHINE\System\ControlSet00x	--> HKLM\System\CurrentControlSet


Free Security Log Resources by Randy

Description Fields in 12

  • Log Name
  • Source
  • Date
  • Event ID
  • Task Category
  • Level
  • Keywords
  • User
  • Computer
  • Description
  • EventType
  • UtcTime
  • ProcessGuid
  • ProcessId
  • Image
  • TargetObject

Supercharger Free Edition


Examples of 12

Registry object added or deleted:
EventType: DeleteValue
UtcTime: 2017-05-11 04:31:15.792
ProcessGuid: {a23eae89-e8bf-5913-0000-0010db9f7109}
ProcessId: 25228
Image: C:\Windows\regedit.exe
TargetObject: \REGISTRY\MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce\New Value #1


Event XML:
 <Event xmlns="">

        <Provider Name="Microsoft-Windows-Sysmon" Guid="{5770385F-C22A-43E0-BF4C-06F5698FFBD9}" />
        <TimeCreated SystemTime="2017-05-11T04:31:15.792607700Z" />
        <Correlation />
        <Execution ProcessID="3188" ThreadID="3836" />
        <Security UserID="S-1-5-18" />
        <Data Name="EventType">DeleteValue</Data>
        <Data Name="UtcTime">2017-05-11 04:31:15.792</Data>
        <Data Name="ProcessGuid">{A23EAE89-E8BF-5913-0000-0010DB9F7109}</Data>
        <Data Name="ProcessId">25228</Data>
        <Data Name="Image">C:\Windows\regedit.exe</Data>
        <Data Name="TargetObject">\REGISTRY\MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce\New Value #1</Data>


Top 10 Windows Security Events to Monitor

Free Tool for Windows Event Collection


Upcoming Webinars
    Additional Resources