Registry Tip #9: Registry Events that can be audited

Hits: Failed to execute CGI : Win32 Error Code = 3


Events to Audit Description
Query Value Reads a value entry from a Registry key
Set Value Sets value entries in a Registry key
Create Subkey Create subkeys on a selected Registry key
Enumerate Subkeys Audits events that attempt to identify the subkeys of a Registry key such as expanding the tree view
Notify Notifies events from a ket in the Registry
Create link Creates a symbolic link in a particular key
Delete Deletes a Registry object
Write DAC Changes security permissions on a key
Read Control Reads the security permissions of a key



A must have for NT administrators in corporate or governmental organizations or anyone being audited by a large outside audit firm.
It is not a secrets type guide but it has excellent sound advice and its used by PriceWaterhouse's auditors as a guide.