Skip to content

Commit

Permalink
Update Sysmon.md
Browse files Browse the repository at this point in the history
  • Loading branch information
darkoperator authored Jul 10, 2020
1 parent 878846c commit 5a28b91
Showing 1 changed file with 2 additions and 2 deletions.
4 changes: 2 additions & 2 deletions Sysmon.md
Original file line number Diff line number Diff line change
Expand Up @@ -1643,7 +1643,7 @@ a VDI environment

## Registry Actions

Sysmon has the capability to monitor for three major actions against Registry
Sysmon has the capability to monitor for three major actions against the Registry

* **EventID 12** - Registry object added or deleted

Expand Down Expand Up @@ -1719,7 +1719,7 @@ In registry events, the value name is appended to the full key path with a \"\\\

Default key values are named \"\\(Default)\"

When filtering for keys or values in HKCU, use **contains** or **end with** when filtering against **TargetObject** since the SID of the user is appended after the Hive name.
When filtering for keys or values in HKCU, use **contains** or **ends with** when filtering against **TargetObject** since the SID of the user is appended after the Hive name.

![HKCU Test](./media/image51.png)

Expand Down

0 comments on commit 5a28b91

Please sign in to comment.