Previous Topic: Signature Violation ActionNext Topic: Suspicious Service/Daemon Activity Action


Windows Registry Modify Action

The action Windows Registry Modify deals with the expression of event information pertaining to the modification of Windows Registry. Changes include adding, deleting, modifying keys and values.

Information

Level

Source - User Information

Secondary

Source - Host Information

Tertiary

Source - Object Information

Tertiary

Source - Process Information

Tertiary

Source - Group Information

Tertiary

Dest - User Information

Tertiary

Dest - Host Information

Primary

Dest - Object Information

Primary

Dest - Group Information

Tertiary

Agent - Information

Primary

Agent - Host Information

Primary

Event Source - Host Information

Primary

Event Source - Information

Tertiary

Event - Information

Primary

Result - Information

Primary

Result

event_result

event_severity

Success

S

3

Failure

F

3