Sysmon Event ID 13: Registry value set
- Event ID
- 13
- Channel
- Microsoft-Windows-Sysmon/Operational
- Provider
- Microsoft-Windows-Sysmon
- Log file
- Microsoft-Windows-Sysmon%4Operational.evtx
- Category
- Registry
- Default logging
- Needs configuration
What event 13 means
Sysmon event 13 records a registry value write: the value path in TargetObject, the data in Details, and the writing process. Numeric values appear as DWORD (0x...) or QWORD (...); string values show their text; binary data is not reproduced.
This is the event that shows Run key persistence, new service ImagePath values, disabled security features (for example Defender or UAC settings) and IFEO debugger hijacks, in one record with the responsible process.
Volume depends entirely on the configuration; target known persistence and security-setting paths.
When it is logged
Sysmon installed; filter with <RegistryEvent> rules in the configuration.
Key fields
| Field | What it tells you |
|---|---|
| EventType | Always SetValue for this event. |
| ProcessGuid | Process that wrote the value; pivot to its event 1. |
| Image | Executable that wrote the value. |
| TargetObject | Full path of the value, e.g. HKU\<SID>\Software\Microsoft\Windows\CurrentVersion\Run\<name>. |
| Details | Data written. For Run keys and service ImagePath this is the command that will run; for DWORD settings, e.g. DWORD (0x00000001). |
| User | Account of the process (newer Sysmon versions). |
Common benign sources
- Applications registering auto-start helpers in Run keys at install time.
- Windows and Group Policy writing settings, Explorer updating per-user state (very frequent).
What attackers do that produces it
- Run or RunOnce values pointing to a binary or script in a user-writable folder.
- Service
ImagePathchanged to a new binary, or aDebuggervalue set under Image File Execution Options. - Security settings weakened, such as Defender or firewall policy values set to disable protection.
Investigation tips
- Read Details and check whether the referenced path exists and was recently written (event 11).
- Pivot on ProcessGuid to event 1 —
reg.exe, PowerShell or an unknown binary writing Run keys stands out. - Check for the matching key creation (event 12) and for the persisted program running after reboot (event 1).
MITRE ATT&CK techniques
| Technique | Tactics |
|---|---|
| T1547.001 Boot or Logon Autostart Execution: Registry Run Keys / Startup Folder | Persistence, Privilege Escalation |
| T1112 Modify Registry | Defense Impairment, Persistence |
| T1543.003 Create or Modify System Process: Windows Service | Persistence, Privilege Escalation |
| T1546.015 Event Triggered Execution: Component Object Model Hijacking | Privilege Escalation, Persistence |
MITRE ATT&CK v19.2. Technique and tactic names are MITRE's.
Sigma rules for this event
236 SigmaHQ detection rules (release r2026-07-01) target this event. Showing the 25 highest-severity rules.
- Critical · 4
- High · 131
- Medium · 92
- Low · 8
- Info · 1
- CriticalPotential Credential Dumping Via LSASS SilentProcessExit TechniqueRule by Florian Roth (Nextron Systems), SigmaHQ, DRL 1.1
- CriticalRegistry Entries For Azorult MalwareRule by Trent Liffick, SigmaHQ, DRL 1.1
- CriticalSticky Key Like Backdoor Usage - RegistryRule by Florian Roth (Nextron Systems), @twjackomo, Jonhnathan Ribeiro, oscd.community, SigmaHQ, DRL 1.1
- CriticalWindows Credential Editor RegistryRule by Florian Roth (Nextron Systems), SigmaHQ, DRL 1.1
- HighAdd Debugger Entry To Hangs Key For PersistenceRule by Nasreddine Bencherchali (Nextron Systems), SigmaHQ, DRL 1.1
- HighAMSI Disabled via Registry ModificationRule by Swachchhanda Shrawan Poudel (Nextron Systems), SigmaHQ, DRL 1.1
- HighAntivirus Filter Driver Disallowed On Dev Drive - RegistryRule by @kostastsale, Nasreddine Bencherchali (Nextron Systems), SigmaHQ, DRL 1.1
- HighBypass UAC Using DelegateExecuteRule by frack113, SigmaHQ, DRL 1.1
- HighBypass UAC Using Event ViewerRule by frack113, SigmaHQ, DRL 1.1
- HighBypass UAC Using SilentCleanup TaskRule by frack113, Nextron Systems, SigmaHQ, DRL 1.1
- HighChange the Fax DllRule by frack113, SigmaHQ, DRL 1.1
- HighChange User Account Associated with the FAX ServiceRule by frack113, SigmaHQ, DRL 1.1
- HighChange Winevt Channel Access Permission Via RegistryRule by frack113, SigmaHQ, DRL 1.1
- HighCMSTP Execution Registry EventRule by Nik Seetharaman, SigmaHQ, DRL 1.1
- HighCOM Hijack via SdcltRule by Omkar Gudhate, SigmaHQ, DRL 1.1
- HighCOM Object Hijacking Via Modification Of Default System CLSID Default ValueRule by Nasreddine Bencherchali (Nextron Systems), SigmaHQ, DRL 1.1
- HighCreation of a Local Hidden User Account by RegistryRule by Christian Burkard (Nextron Systems), SigmaHQ, DRL 1.1
- HighCustom File Open Handler Executes PowerShellRule by CD_R0M_, SigmaHQ, DRL 1.1
- HighDefault RDP Port Changed to Non Standard PortRule by frack113, SigmaHQ, DRL 1.1
- HighDHCP Callout DLL InstallationRule by Dimitrios Slamaris, SigmaHQ, DRL 1.1
- HighDirectory Service Restore Mode(DSRM) Registry Value TamperingRule by Nischal Khadgi, SigmaHQ, DRL 1.1
- HighDisable Macro Runtime Scan ScopeRule by Nasreddine Bencherchali (Nextron Systems), SigmaHQ, DRL 1.1
- HighDisable PUA Protection on Windows DefenderRule by Austin Songer @austinsonger, SigmaHQ, DRL 1.1
- HighDisable Security Events Logging Adding Reg Key MiniNtRule by Ilyas Ochkov, oscd.community, SigmaHQ, DRL 1.1
- HighDisable Windows Defender Functionalities Via Registry KeysRule by AlertIQ, Ján Trenčanský, frack113, Nasreddine Bencherchali, Swachchhanda Shrawan Poudel, SigmaHQ, DRL 1.1
Rules by their named authors, published by SigmaHQ under the Detection Rule License (DRL) 1.1.
Run these rules on your logs
Drop a .evtx file into the viewer: all 2,395 bundled SigmaHQ rules run locally in your browser. Nothing is uploaded.