Splunk Search

What is the correct filter to find persistence in Windows registry?

tonyfer
Observer

Hi 

I'm investigating Windows log in Splunk, struggling to apply the correct filter.

What filter do I need to apply to find the persistence in the Windows registry?

What filter do I need to apply to find the Sysmon id 13 events to find the registry key used to maintain persistence in Windows?

Filter for what port number is listening for an incoming connection, using Sysmon  12 and sysmon13 event IDs.

my current search: index=*

Any assistance will be immensely appreciated

0 Karma

ITWhisperer
SplunkTrust
SplunkTrust

Similar to this question Re: How to Identify windows registry key use for p... - Splunk Community

Do you have examples of the events you are dealing with?

0 Karma

tonyfer
Observer

Hi

I want to search for sysmon events in splunk

 my current search: index=* sourcetype="WinEventLog:Microsoft-Windows-sysmon/operation" Registry

I'm trying to identify any persistence in the system, is that the correct filter for Splunk search?

 

Thanks

0 Karma

ITWhisperer
SplunkTrust
SplunkTrust

So, your question is not really a Splunk question, it is more about your data, and how to interpret your data to identify the "persistence" events. Without knowledge of your data, it is difficult for us to advise. Perhaps if you shared some of your events, anonymised of course, we might be able to make some suggestions.

Having said that, a quick google search (which you could have done yourself!) returns this link to Microsoft, which seems to indicate that events 12, 13 and 14 are to do with the Registry. Perhaps you could start with those.

0 Karma
Get Updates on the Splunk Community!

Index This | What is broken 80% of the time by February?

December 2025 Edition   Hayyy Splunk Education Enthusiasts and the Eternally Curious!    We’re back with this ...

Unlock Faster Time-to-Value on Edge and Ingest Processor with New SPL2 Pipeline ...

Hello Splunk Community,   We're thrilled to share an exciting update that will help you manage your data more ...

Splunk MCP & Agentic AI: Machine Data Without Limits

Discover how the Splunk Model Context Protocol (MCP) Server can revolutionize the way your organization uses ...