Environment
- Enterprise EDR: All Supported Versions
- Windows OS: All Supported Versions
Question
Is it possible to see the registry changes in the regmod events?
Answer
Regmod events show the registry key that was changed they do not show what the actual change was
Additional Notes
The Live Response API can be used to query registry values
here
Related Content