Sysmon Event ID 14: Registry key or value renamed
- Event ID
- 14
- Channel
- Microsoft-Windows-Sysmon/Operational
- Provider
- Microsoft-Windows-Sysmon
- Log file
- Microsoft-Windows-Sysmon%4Operational.evtx
- Category
- Registry
- Default logging
- Needs configuration
What event 14 means
Sysmon event 14 records a rename in the registry: TargetObject holds the original path and NewName the new one. Renames are uncommon in normal operation, which makes them easy to review.
Attackers can rename keys to swap a prepared configuration into place in one step, or to temporarily disable a security setting and restore it later. The event is covered by the same <RegistryEvent> rules as events 12 and 13.
When it is logged
Sysmon installed; filter with <RegistryEvent> rules in the configuration.
Key fields
| Field | What it tells you |
|---|---|
| EventType | RenameKey for this event. |
| ProcessGuid | Process that performed the rename. |
| Image | Executable that performed the rename. |
| TargetObject | Original registry path. |
| NewName | New name of the key or value. |
| User | Account of the process (newer Sysmon versions). |
Common benign sources
- Installers and configuration tools renaming keys during upgrades.
- Registry editor use by administrators.
What attackers do that produces it
- Renaming a prepared key into a persistence location (services, COM, Run) to activate it at once.
- Renaming security product keys to disable them without deleting them.
Investigation tips
- Pivot on ProcessGuid to event 1 and review nearby events 12 and 13 from the same process.
- Check whether NewName lands in a persistence or security-setting path.
MITRE ATT&CK techniques
| Technique | Tactics |
|---|---|
| T1112 Modify Registry | Defense Impairment, Persistence |
MITRE ATT&CK v19.2. Technique and tactic names are MITRE's.
Sigma rules for this event
31 SigmaHQ detection rules (release r2026-07-01) target this event. Showing the 25 highest-severity rules.
- Critical · 3
- High · 19
- Medium · 9
- CriticalPotential Credential Dumping Via LSASS SilentProcessExit TechniqueRule by Florian Roth (Nextron Systems), SigmaHQ, DRL 1.1
- CriticalSticky Key Like Backdoor Usage - RegistryRule by Florian Roth (Nextron Systems), @twjackomo, Jonhnathan Ribeiro, oscd.community, SigmaHQ, DRL 1.1
- CriticalWindows Credential Editor RegistryRule by Florian Roth (Nextron Systems), SigmaHQ, DRL 1.1
- HighCMSTP Execution Registry EventRule by Nik Seetharaman, SigmaHQ, DRL 1.1
- HighCreation of a Local Hidden User Account by RegistryRule by Christian Burkard (Nextron Systems), SigmaHQ, DRL 1.1
- HighDisable Security Events Logging Adding Reg Key MiniNtRule by Ilyas Ochkov, oscd.community, SigmaHQ, DRL 1.1
- HighDLL Load via LSASSRule by Florian Roth (Nextron Systems), SigmaHQ, DRL 1.1
- HighEsentutl Volume Shadow Copy Service KeysRule by Roberto Rodriguez (Cyb3rWard0g), OTR (Open Threat Research), SigmaHQ, DRL 1.1
- HighHybridConnectionManager Service Installation - RegistryRule by Roberto Rodriguez (Cyb3rWard0g), OTR (Open Threat Research), SigmaHQ, DRL 1.1
- HighNarrator's Feedback-Hub PersistenceRule by Dmitriy Lifanov, oscd.community, SigmaHQ, DRL 1.1
- HighNetNTLM Downgrade Attack - RegistryRule by Florian Roth (Nextron Systems), wagga, Nasreddine Bencherchali (Splunk STRT), SigmaHQ, DRL 1.1
- HighPotential Qakbot Registry ActivityRule by Hieu Tran, SigmaHQ, DRL 1.1
- HighRedMimicry Winnti Playbook Registry ManipulationRule by Alexander Rausch, SigmaHQ, DRL 1.1
- HighRegistry Persistence Mechanisms in Recycle BinRule by frack113, SigmaHQ, DRL 1.1
- HighSecurity Support Provider (SSP) Added to LSA ConfigurationRule by iwillkeepwatch, SigmaHQ, DRL 1.1
- HighShell Open Registry Keys ManipulationRule by Christian Burkard (Nextron Systems), SigmaHQ, DRL 1.1
- HighSuspicious Camera and Microphone AccessRule by Den Iuzvyk, SigmaHQ, DRL 1.1
- HighSuspicious Run Key from DownloadRule by Florian Roth (Nextron Systems), Swachchhanda Shrawan Poude (Nextron Systems), SigmaHQ, DRL 1.1
- HighUAC Bypass Via WsresetRule by oscd.community, Dmitry Uchakin, SigmaHQ, DRL 1.1
- HighWdigest CredGuard Registry ModificationRule by Roberto Rodriguez (Cyb3rWard0g), OTR (Open Threat Research), SigmaHQ, DRL 1.1
- HighWindows Defender Threat Severity Default Action ModifiedRule by Matt Anderson (Huntress), SigmaHQ, DRL 1.1
- HighWINEKEY Registry ModificationRule by omkar72, SigmaHQ, DRL 1.1
- MediumAtbroker Registry ChangeRule by Mateusz Wydra, oscd.community, SigmaHQ, DRL 1.1
- MediumNew DLL Added to AppCertDlls Registry KeyRule by Ilyas Ochkov, oscd.community, SigmaHQ, DRL 1.1
- MediumNew DLL Added to AppInit_DLLs Registry KeyRule by Ilyas Ochkov, oscd.community, Tim Shelton, SigmaHQ, DRL 1.1
Rules by their named authors, published by SigmaHQ under the Detection Rule License (DRL) 1.1.
Run these rules on your logs
Drop a .evtx file into the viewer: all 2,395 bundled SigmaHQ rules run locally in your browser. Nothing is uploaded.