Skip to content
Security

Event ID 4657: Registry value modified

A registry value was modifiedSecurity event 4657 records a created, changed or deleted registry value on an audited key, with old and new data and the process that made the change.
4657
Event ID
4657
Channel
Security
Provider
Microsoft-Windows-Security-Auditing
Log file
Security.evtx
Category
Registry
Default logging
Needs configuration

What event 4657 means

Event 4657 is written when a value under a registry key with an auditing SACL is created, modified or deleted. Unlike most object-access events it carries the actual content: ObjectValueName, OldValue and NewValue, plus the process and account responsible.

That makes it a native alternative to Sysmon event 13 for a small set of high-value keys such as Run keys, service configuration, LSA settings or Defender policies. It only covers keys you have explicitly audited, so coverage depends entirely on the SACLs deployed.

The event relates to the value, not the key: key creation and deletion show up as 4663/4660, and a 4656 for the same handle usually precedes the 4657.

When it is logged

Audit policy / configuration

Advanced Audit Policy Configuration > Object Access > Audit Registry (Success), plus a SACL on the key auditing Set Value (and Delete for deletions).

Auditing whole hives is not practical; target specific keys. ObjectName uses kernel paths such as \REGISTRY\MACHINE\SOFTWARE\... and \REGISTRY\USER\<SID>\....

Key fields

FieldWhat it tells you
SubjectUserNameAccount that changed the value.
SubjectLogonIdLogon session of that account; pivot to 4624 and 4688.
ObjectNameRegistry key path in kernel form, e.g. \REGISTRY\MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run.
ObjectValueNameName of the value that was created, modified or deleted.
OperationTypeWhat happened to the value, rendered as "New registry value created", "Existing registry value modified" or "Registry value deleted".
OldValueTypeRegistry type of the previous data (e.g. REG_SZ, REG_DWORD); - for a new value.
OldValuePrevious data of the value.
NewValueTypeRegistry type of the new data.
NewValueNew data written — the command line of a Run entry, a service ImagePath, a policy flag.
HandleIdHandle used for the change; links to the preceding 4656.
ProcessNameFull path of the process that wrote the value.
ProcessIdHexadecimal PID of that process.

Common benign sources

  • Software installers and updaters writing to Run keys or their own service keys.
  • Group Policy processing rewriting policy values on every refresh.
  • Administrators changing settings with regedit.exe or reg.exe during maintenance.

What attackers do that produces it

  • Persistence through a new value under a Run or RunOnce key pointing to a binary in a user-writable folder.
  • Changing a service ImagePath to run an attacker binary.
  • Weakening defenses by setting security-relevant values, for example disabling Defender features through policy keys.

Investigation tips

  • Read NewValue first; a path in AppData, Temp or ProgramData, or an encoded command, is a strong lead.
  • Check ProcessName; reg.exe, powershell.exe or an unknown binary writing autostart keys deserves review.
  • Pivot SubjectLogonId to 4688 to find the command line that made the change.
  • Compare OldValue and NewValue to understand what was replaced and restore it if needed.

MITRE ATT&CK techniques

TechniqueTactics
T1112 Modify RegistryDefense Impairment, Persistence
T1547.001 Boot or Logon Autostart Execution: Registry Run Keys / Startup FolderPersistence, Privilege Escalation

MITRE ATT&CK v19.2. Technique and tactic names are MITRE's.

Sigma rules for this event

5 SigmaHQ detection rules (release r2026-07-01) target this event.

  • High · 3
  • Medium · 2

Rules by their named authors, published by SigmaHQ under the Detection Rule License (DRL) 1.1.

Run these rules on your logs

Drop a .evtx file into the viewer: all 2,395 bundled SigmaHQ rules run locally in your browser. Nothing is uploaded.

Sources and further reading