Skip to content
Sysmon

Sysmon Event ID 12: Registry key created or deleted

RegistryEvent (Object create and delete)Sysmon event 12 logs registry keys and values being created or deleted, with the process responsible. Watch autostart keys, services and COM entries.
12
Event ID
12
Channel
Microsoft-Windows-Sysmon/Operational
Provider
Microsoft-Windows-Sysmon
Log file
Microsoft-Windows-Sysmon%4Operational.evtx
Category
Registry
Default logging
Needs configuration

What event 12 means

Sysmon event 12 covers registry key creation and deletion and value deletion. EventType tells which, TargetObject gives the path, and the process fields name who did it. Value writes are in event 13 and renames in event 14.

Sysmon shortens root keys: HKLM for HKEY_LOCAL_MACHINE, HKU for HKEY_USERS (per-user hives appear as HKU\<SID>\...), HKCR for HKEY_LOCAL_MACHINE\Classes, and HKLM\System\CurrentControlSet for the active control set.

The registry is extremely busy, so configurations include persistence and defense-evasion locations: Run keys, services, COM CLSIDs, Image File Execution Options, security product settings.

When it is logged

Audit policy / configuration

Sysmon installed; filter with <RegistryEvent> rules in the configuration.

Key fields

FieldWhat it tells you
EventTypeKind of operation.
ValueMeaning
CreateKeyA registry key was created.
DeleteKeyA registry key was deleted.
DeleteValueA registry value was deleted.
ProcessGuidProcess that changed the registry; pivot to its event 1.
ImageExecutable that changed the registry.
TargetObjectFull registry path in Sysmon's abbreviated form, e.g. HKLM\System\CurrentControlSet\Services\<name>.
UserAccount of the process (newer Sysmon versions).

Common benign sources

  • Installers and updaters creating product keys and service entries.
  • Group Policy processing and Windows components creating and deleting keys at boot and logon.

What attackers do that produces it

  • A new key under HKLM\System\CurrentControlSet\Services created by a non-installer process (service persistence).
  • New COM CLSID keys under HKU\<SID>\Software\Classes\CLSID for COM hijacking.
  • Deleting Run keys, services or tool traces after use to clean up.

Investigation tips

  • Pivot on ProcessGuid to event 1 to see who changed the registry.
  • Follow up with event 13 on the same key to read the values that were set.
  • For service keys, correlate with System 7045 and Security 4697.

MITRE ATT&CK techniques

TechniqueTactics
T1112 Modify RegistryDefense Impairment, Persistence
T1547.001 Boot or Logon Autostart Execution: Registry Run Keys / Startup FolderPersistence, Privilege Escalation
T1543.003 Create or Modify System Process: Windows ServicePersistence, Privilege Escalation
T1546.015 Event Triggered Execution: Component Object Model HijackingPrivilege Escalation, Persistence

MITRE ATT&CK v19.2. Technique and tactic names are MITRE's.

Sigma rules for this event

43 SigmaHQ detection rules (release r2026-07-01) target this event. Showing the 25 highest-severity rules.

  • Critical · 4
  • High · 24
  • Medium · 15

Rules by their named authors, published by SigmaHQ under the Detection Rule License (DRL) 1.1.

Run these rules on your logs

Drop a .evtx file into the viewer: all 2,395 bundled SigmaHQ rules run locally in your browser. Nothing is uploaded.

Sources and further reading