Windows boot registry key modified
このページは日本語には対応しておりません。随時翻訳に取り組んでいます。翻訳に関してご質問やご意見ございましたら、お気軽にご連絡ください。
Goal
Detect modifications of Windows boot registry keys.
Strategy
Various compliance frameworks, including PCI DSS, SOC, and CIS require monitoring of critical system and configuration files. On Windows, a key configurations for how the operating system boots can be found in ‘HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\IniFileMapping\system.ini\boot’.
Triage and response
- Identify which user or process modified the registry key.
- If these changes were not authorized, and you cannot confirm the safety of the changes, roll back the host in question to an acceptable configuration.
Requires Agent version 7.52 or later