Skip to content

Latest commit

 

History

History
29 lines (22 loc) · 703 Bytes

530701a5-359e-482f-af68-1ae8405e4f69.md

File metadata and controls

29 lines (22 loc) · 703 Bytes

Mappings: Windows - Security - 4618

Input Requirements

Input Value
Vendor Microsoft
Product Windows
Log Format Windows
Event ID Regex Pattern Security-4618

Record Output

Output Value
Vendor Microsoft
Product Windows
Record Type Audit

Fields Mapped

Cloud SIEM Schema Field Original Record Key Notes
description None The static text A registry value was modified is populated in this schema field.
device_hostname EventData.ComputerName
user_authDomain EventData.TargetUserDomain
user_userId EventData.TargetUserSid
user_username EventData.TargetUserName