Event ID 4657: Registry value modified
- Event ID
- 4657
- Channel
- Security
- Provider
- Microsoft-Windows-Security-Auditing
- Log file
- Security.evtx
- Category
- Registry
- Default logging
- Needs configuration
What event 4657 means
Event 4657 is written when a value under a registry key with an auditing SACL is created, modified or deleted. Unlike most object-access events it carries the actual content: ObjectValueName, OldValue and NewValue, plus the process and account responsible.
That makes it a native alternative to Sysmon event 13 for a small set of high-value keys such as Run keys, service configuration, LSA settings or Defender policies. It only covers keys you have explicitly audited, so coverage depends entirely on the SACLs deployed.
The event relates to the value, not the key: key creation and deletion show up as 4663/4660, and a 4656 for the same handle usually precedes the 4657.
When it is logged
Advanced Audit Policy Configuration > Object Access > Audit Registry (Success), plus a SACL on the key auditing Set Value (and Delete for deletions).
Auditing whole hives is not practical; target specific keys. ObjectName uses kernel paths such as \REGISTRY\MACHINE\SOFTWARE\... and \REGISTRY\USER\<SID>\....
Key fields
| Field | What it tells you |
|---|---|
| SubjectUserName | Account that changed the value. |
| SubjectLogonId | Logon session of that account; pivot to 4624 and 4688. |
| ObjectName | Registry key path in kernel form, e.g. \REGISTRY\MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run. |
| ObjectValueName | Name of the value that was created, modified or deleted. |
| OperationType | What happened to the value, rendered as "New registry value created", "Existing registry value modified" or "Registry value deleted". |
| OldValueType | Registry type of the previous data (e.g. REG_SZ, REG_DWORD); - for a new value. |
| OldValue | Previous data of the value. |
| NewValueType | Registry type of the new data. |
| NewValue | New data written — the command line of a Run entry, a service ImagePath, a policy flag. |
| HandleId | Handle used for the change; links to the preceding 4656. |
| ProcessName | Full path of the process that wrote the value. |
| ProcessId | Hexadecimal PID of that process. |
Common benign sources
- Software installers and updaters writing to Run keys or their own service keys.
- Group Policy processing rewriting policy values on every refresh.
- Administrators changing settings with
regedit.exeorreg.exeduring maintenance.
What attackers do that produces it
- Persistence through a new value under a Run or RunOnce key pointing to a binary in a user-writable folder.
- Changing a service
ImagePathto run an attacker binary. - Weakening defenses by setting security-relevant values, for example disabling Defender features through policy keys.
Investigation tips
- Read
NewValuefirst; a path inAppData,TemporProgramData, or an encoded command, is a strong lead. - Check
ProcessName;reg.exe,powershell.exeor an unknown binary writing autostart keys deserves review. - Pivot
SubjectLogonIdto 4688 to find the command line that made the change. - Compare
OldValueandNewValueto understand what was replaced and restore it if needed.
MITRE ATT&CK techniques
MITRE ATT&CK v19.2. Technique and tactic names are MITRE's.
Sigma rules for this event
5 SigmaHQ detection rules (release r2026-07-01) target this event.
- High · 3
- Medium · 2
- HighETW Logging Disabled In .NET Processes - RegistryRule by Roberto Rodriguez (Cyb3rWard0g), OTR (Open Threat Research), SigmaHQ, DRL 1.1
- HighNetNTLM Downgrade AttackRule by Florian Roth (Nextron Systems), wagga, SigmaHQ, DRL 1.1
- HighSysmon Channel Reference DeletionRule by Roberto Rodriguez (Cyb3rWard0g), OTR (Open Threat Research), SigmaHQ, DRL 1.1
- MediumProcesses Accessing the Microphone and WebcamRule by Roberto Rodriguez (Cyb3rWard0g), OTR (Open Threat Research), SigmaHQ, DRL 1.1
- MediumWindows Defender Exclusion List ModifiedRule by @BarryShooshooga, SigmaHQ, DRL 1.1
Rules by their named authors, published by SigmaHQ under the Detection Rule License (DRL) 1.1.
Run these rules on your logs
Drop a .evtx file into the viewer: all 2,395 bundled SigmaHQ rules run locally in your browser. Nothing is uploaded.