Registry Key

reg_key

The registry key object describes a Windows registry key.

Attributes

CaptionNameTypeDescription
Systemis_systemBoolean

The indication of whether the object is part of the operating system.

Modified Timemodified_timeTimestamp

The time when the registry key was last modified.

PathpathString

The full path to the registry key.

Raw Dataraw_dataJSON

Group:context
The event data as received from the event source.

Record IDrecord_idString

Group:primary
Unique identifier for the object

Security Descriptorsecurity_descriptorString

The security descriptor of the registry key.

UnmappedunmappedUnmapped[]

Data from the source that was not mapped into the schema.

Relationships

Registry Key shown in context

Inbound Relationships

These objects and events reference Registry Key in their attributes:

Outbound Relationships

Registry Key references the following objects and events in its attributes:

This page describes ocsf-1.4.0