table

DeviceRegistryEvents

DeviceRegistryEvents contains registry entry creation, modification, and related registry activity reported by Microsoft Defender for Endpoint.

tablesCurrent

Relationships

Schema

FieldTypeDescriptionCopy
TimestampdatetimeDate and time when the event was recorded.
DeviceIdstringUnique identifier for the device in the service.
DeviceNamestringFully qualified domain name of the device.
ActionTypestringType of registry activity that triggered the event.
RegistryKeystringRegistry key that the recorded action was applied to.
RegistryValueNamestringName of the registry value that the recorded action was applied to.
RegistryValueDatastringData of the registry value that the recorded action was applied to.
RegistryValueTypestringData type of the registry value that the recorded action was applied to.
InitiatingProcessAccountSidstringSecurity identifier of the account that ran the process responsible for the registry event.