Event ID 14
Logs registry key and value rename operationsSource:
Microsoft-Windows-Sysmon
Category:
Registry object renamed
Registry object renamed: RuleName: %1!s! EventType: %2!s! UtcTime: %3!s! ProcessGuid: %4!s! ProcessId: %5!s! Image: %6!s! TargetObject: %7!s! NewName: %8!s! User: %9!s!
Registry key and value rename operations map to this event type, recording the new name of the key or value that was renamed.
LEFT/RIGHT arrow keys for navigation
Back to List