Skip to content
Sysmon

Sysmon Event ID 14: Registry key or value renamed

RegistryEvent (Key and Value Rename)Sysmon event 14 logs a registry key or value being renamed, with the old path and the new name. Rare, and occasionally used to hide or stage persistence.
14
Event ID
14
Channel
Microsoft-Windows-Sysmon/Operational
Provider
Microsoft-Windows-Sysmon
Log file
Microsoft-Windows-Sysmon%4Operational.evtx
Category
Registry
Default logging
Needs configuration

What event 14 means

Sysmon event 14 records a rename in the registry: TargetObject holds the original path and NewName the new one. Renames are uncommon in normal operation, which makes them easy to review.

Attackers can rename keys to swap a prepared configuration into place in one step, or to temporarily disable a security setting and restore it later. The event is covered by the same <RegistryEvent> rules as events 12 and 13.

When it is logged

Audit policy / configuration

Sysmon installed; filter with <RegistryEvent> rules in the configuration.

Key fields

FieldWhat it tells you
EventTypeRenameKey for this event.
ProcessGuidProcess that performed the rename.
ImageExecutable that performed the rename.
TargetObjectOriginal registry path.
NewNameNew name of the key or value.
UserAccount of the process (newer Sysmon versions).

Common benign sources

  • Installers and configuration tools renaming keys during upgrades.
  • Registry editor use by administrators.

What attackers do that produces it

  • Renaming a prepared key into a persistence location (services, COM, Run) to activate it at once.
  • Renaming security product keys to disable them without deleting them.

Investigation tips

  • Pivot on ProcessGuid to event 1 and review nearby events 12 and 13 from the same process.
  • Check whether NewName lands in a persistence or security-setting path.

MITRE ATT&CK techniques

TechniqueTactics
T1112 Modify RegistryDefense Impairment, Persistence

MITRE ATT&CK v19.2. Technique and tactic names are MITRE's.

Sigma rules for this event

31 SigmaHQ detection rules (release r2026-07-01) target this event. Showing the 25 highest-severity rules.

  • Critical · 3
  • High · 19
  • Medium · 9

Rules by their named authors, published by SigmaHQ under the Detection Rule License (DRL) 1.1.

Run these rules on your logs

Drop a .evtx file into the viewer: all 2,395 bundled SigmaHQ rules run locally in your browser. Nothing is uploaded.

Sources and further reading