Windows Registry Key Creation (7f70fae7-a68d-4730-a83a-f260b9606129)
Initial construction of a new registry key within the Windows operating system.
Data Collection Measures:
- Windows Event Logs
- Event ID 4656 - Registry Object Handle Requested: Tracks registry key access, including newly created keys.
- Event ID 4657 - Registry Value Modification: Detects modifications to an existing registry key after creation.
- Sysmon (System Monitor) for Windows
- Sysmon Event ID 12 - Registry Key Created: Logs when a new registry key is created.