Skip to content
Sysmon

Sysmon Event ID 13: Registry value set

RegistryEvent (Value Set)Sysmon event 13 logs a registry value being written, with the data for DWORD, QWORD and string values. The main Sysmon event for registry persistence.
13
Event ID
13
Channel
Microsoft-Windows-Sysmon/Operational
Provider
Microsoft-Windows-Sysmon
Log file
Microsoft-Windows-Sysmon%4Operational.evtx
Category
Registry
Default logging
Needs configuration

What event 13 means

Sysmon event 13 records a registry value write: the value path in TargetObject, the data in Details, and the writing process. Numeric values appear as DWORD (0x...) or QWORD (...); string values show their text; binary data is not reproduced.

This is the event that shows Run key persistence, new service ImagePath values, disabled security features (for example Defender or UAC settings) and IFEO debugger hijacks, in one record with the responsible process.

Volume depends entirely on the configuration; target known persistence and security-setting paths.

When it is logged

Audit policy / configuration

Sysmon installed; filter with <RegistryEvent> rules in the configuration.

Key fields

FieldWhat it tells you
EventTypeAlways SetValue for this event.
ProcessGuidProcess that wrote the value; pivot to its event 1.
ImageExecutable that wrote the value.
TargetObjectFull path of the value, e.g. HKU\<SID>\Software\Microsoft\Windows\CurrentVersion\Run\<name>.
DetailsData written. For Run keys and service ImagePath this is the command that will run; for DWORD settings, e.g. DWORD (0x00000001).
UserAccount of the process (newer Sysmon versions).

Common benign sources

  • Applications registering auto-start helpers in Run keys at install time.
  • Windows and Group Policy writing settings, Explorer updating per-user state (very frequent).

What attackers do that produces it

  • Run or RunOnce values pointing to a binary or script in a user-writable folder.
  • Service ImagePath changed to a new binary, or a Debugger value set under Image File Execution Options.
  • Security settings weakened, such as Defender or firewall policy values set to disable protection.

Investigation tips

  • Read Details and check whether the referenced path exists and was recently written (event 11).
  • Pivot on ProcessGuid to event 1 — reg.exe, PowerShell or an unknown binary writing Run keys stands out.
  • Check for the matching key creation (event 12) and for the persisted program running after reboot (event 1).

MITRE ATT&CK techniques

TechniqueTactics
T1547.001 Boot or Logon Autostart Execution: Registry Run Keys / Startup FolderPersistence, Privilege Escalation
T1112 Modify RegistryDefense Impairment, Persistence
T1543.003 Create or Modify System Process: Windows ServicePersistence, Privilege Escalation
T1546.015 Event Triggered Execution: Component Object Model HijackingPrivilege Escalation, Persistence

MITRE ATT&CK v19.2. Technique and tactic names are MITRE's.

Sigma rules for this event

236 SigmaHQ detection rules (release r2026-07-01) target this event. Showing the 25 highest-severity rules.

  • Critical · 4
  • High · 131
  • Medium · 92
  • Low · 8
  • Info · 1

Rules by their named authors, published by SigmaHQ under the Detection Rule License (DRL) 1.1.

Run these rules on your logs

Drop a .evtx file into the viewer: all 2,395 bundled SigmaHQ rules run locally in your browser. Nothing is uploaded.

Sources and further reading