System32
Sysmon
Events
Compliance
Validator
TLS/SSL
GeoIP
Tools
Sysmon Events
Source
Microsoft-Windows-Sysmon
(1)
Category
Registry object renamed
(1)
Tags
AppLocker
All AppLocker events
EventSentry
All EventSentry events
Security
All Windows Security events
Sysmon
All Sysmon events
ID
Event Message
14
Registry object renamed: RuleName: %1!s! EventType: %2!s! UtcTime: %3!s! ProcessGuid: %4!s! ProcessId: %5!s! Image: %6!s! TargetObject: %7!s! NewName: %8!s! User: %9!s!