Windows Registry Key Creation

Initial construction of a new registry key within the Windows operating system.

Data Collection Measures:

  • Windows Event Logs
    • Event ID 4656 - Registry Object Handle Requested: Tracks registry key access, including newly created keys.
    • Event ID 4657 - Registry Value Modification: Detects modifications to an existing registry key after creation.
  • Sysmon (System Monitor) for Windows
    • Sysmon Event ID 12 - Registry Key Created: Logs when a new registry key is created.
ID: DC0056
Domains: Enterprise
Version: 2.0
Created: 20 October 2021
Last Modified: 21 October 2025

Log Sources

Name Channel
WinEventLog:Sysmon EventCode=12

Detection Strategy