Sysmon Event ID 12: Registry key created or deleted
- Event ID
- 12
- Channel
- Microsoft-Windows-Sysmon/Operational
- Provider
- Microsoft-Windows-Sysmon
- Log file
- Microsoft-Windows-Sysmon%4Operational.evtx
- Category
- Registry
- Default logging
- Needs configuration
What event 12 means
Sysmon event 12 covers registry key creation and deletion and value deletion. EventType tells which, TargetObject gives the path, and the process fields name who did it. Value writes are in event 13 and renames in event 14.
Sysmon shortens root keys: HKLM for HKEY_LOCAL_MACHINE, HKU for HKEY_USERS (per-user hives appear as HKU\<SID>\...), HKCR for HKEY_LOCAL_MACHINE\Classes, and HKLM\System\CurrentControlSet for the active control set.
The registry is extremely busy, so configurations include persistence and defense-evasion locations: Run keys, services, COM CLSIDs, Image File Execution Options, security product settings.
When it is logged
Sysmon installed; filter with <RegistryEvent> rules in the configuration.
Key fields
| Field | What it tells you | ||||||||
|---|---|---|---|---|---|---|---|---|---|
| EventType | Kind of operation.
| ||||||||
| ProcessGuid | Process that changed the registry; pivot to its event 1. | ||||||||
| Image | Executable that changed the registry. | ||||||||
| TargetObject | Full registry path in Sysmon's abbreviated form, e.g. HKLM\System\CurrentControlSet\Services\<name>. | ||||||||
| User | Account of the process (newer Sysmon versions). |
Common benign sources
- Installers and updaters creating product keys and service entries.
- Group Policy processing and Windows components creating and deleting keys at boot and logon.
What attackers do that produces it
- A new key under
HKLM\System\CurrentControlSet\Servicescreated by a non-installer process (service persistence). - New COM CLSID keys under
HKU\<SID>\Software\Classes\CLSIDfor COM hijacking. - Deleting Run keys, services or tool traces after use to clean up.
Investigation tips
- Pivot on ProcessGuid to event 1 to see who changed the registry.
- Follow up with event 13 on the same key to read the values that were set.
- For service keys, correlate with System 7045 and Security 4697.
MITRE ATT&CK techniques
| Technique | Tactics |
|---|---|
| T1112 Modify Registry | Defense Impairment, Persistence |
| T1547.001 Boot or Logon Autostart Execution: Registry Run Keys / Startup Folder | Persistence, Privilege Escalation |
| T1543.003 Create or Modify System Process: Windows Service | Persistence, Privilege Escalation |
| T1546.015 Event Triggered Execution: Component Object Model Hijacking | Privilege Escalation, Persistence |
MITRE ATT&CK v19.2. Technique and tactic names are MITRE's.
Sigma rules for this event
43 SigmaHQ detection rules (release r2026-07-01) target this event. Showing the 25 highest-severity rules.
- Critical · 4
- High · 24
- Medium · 15
- CriticalPotential Credential Dumping Via LSASS SilentProcessExit TechniqueRule by Florian Roth (Nextron Systems), SigmaHQ, DRL 1.1
- CriticalRegistry Entries For Azorult MalwareRule by Trent Liffick, SigmaHQ, DRL 1.1
- CriticalSticky Key Like Backdoor Usage - RegistryRule by Florian Roth (Nextron Systems), @twjackomo, Jonhnathan Ribeiro, oscd.community, SigmaHQ, DRL 1.1
- CriticalWindows Credential Editor RegistryRule by Florian Roth (Nextron Systems), SigmaHQ, DRL 1.1
- HighCMSTP Execution Registry EventRule by Nik Seetharaman, SigmaHQ, DRL 1.1
- HighCreation of a Local Hidden User Account by RegistryRule by Christian Burkard (Nextron Systems), SigmaHQ, DRL 1.1
- HighDisable Security Events Logging Adding Reg Key MiniNtRule by Ilyas Ochkov, oscd.community, SigmaHQ, DRL 1.1
- HighDLL Load via LSASSRule by Florian Roth (Nextron Systems), SigmaHQ, DRL 1.1
- HighEsentutl Volume Shadow Copy Service KeysRule by Roberto Rodriguez (Cyb3rWard0g), OTR (Open Threat Research), SigmaHQ, DRL 1.1
- HighFolder Removed From Exploit Guard ProtectedFolders List - RegistryRule by Nasreddine Bencherchali (Nextron Systems), SigmaHQ, DRL 1.1
- HighHybridConnectionManager Service Installation - RegistryRule by Roberto Rodriguez (Cyb3rWard0g), OTR (Open Threat Research), SigmaHQ, DRL 1.1
- HighNarrator's Feedback-Hub PersistenceRule by Dmitriy Lifanov, oscd.community, SigmaHQ, DRL 1.1
- HighNetNTLM Downgrade Attack - RegistryRule by Florian Roth (Nextron Systems), wagga, Nasreddine Bencherchali (Splunk STRT), SigmaHQ, DRL 1.1
- HighPotential Qakbot Registry ActivityRule by Hieu Tran, SigmaHQ, DRL 1.1
- HighRedMimicry Winnti Playbook Registry ManipulationRule by Alexander Rausch, SigmaHQ, DRL 1.1
- HighRegistry Persistence Mechanisms in Recycle BinRule by frack113, SigmaHQ, DRL 1.1
- HighRemoval Of AMSI Provider Registry KeysRule by frack113, SigmaHQ, DRL 1.1
- HighRunMRU Registry Key Deletion - RegistryRule by Swachchhanda Shrawan Poudel (Nextron Systems), SigmaHQ, DRL 1.1
- HighSecurity Support Provider (SSP) Added to LSA ConfigurationRule by iwillkeepwatch, SigmaHQ, DRL 1.1
- HighShell Open Registry Keys ManipulationRule by Christian Burkard (Nextron Systems), SigmaHQ, DRL 1.1
- HighSuspicious Camera and Microphone AccessRule by Den Iuzvyk, SigmaHQ, DRL 1.1
- HighSuspicious Run Key from DownloadRule by Florian Roth (Nextron Systems), Swachchhanda Shrawan Poude (Nextron Systems), SigmaHQ, DRL 1.1
- HighTerminal Server Client Connection History Cleared - RegistryRule by Christian Burkard (Nextron Systems), SigmaHQ, DRL 1.1
- HighUAC Bypass Via WsresetRule by oscd.community, Dmitry Uchakin, SigmaHQ, DRL 1.1
- HighWdigest CredGuard Registry ModificationRule by Roberto Rodriguez (Cyb3rWard0g), OTR (Open Threat Research), SigmaHQ, DRL 1.1
Rules by their named authors, published by SigmaHQ under the Detection Rule License (DRL) 1.1.
Run these rules on your logs
Drop a .evtx file into the viewer: all 2,395 bundled SigmaHQ rules run locally in your browser. Nothing is uploaded.