13241300x8000000000000000280570Microsoft-Windows-Sysmon/Operationalar-win.nas.domain-SetValue2024-12-08 16:41:59.911{38b9f94a-cc57-6755-b698-000000002f03}448C:\Windows\system32\reg.exeHKU\S-1-5-21-2591002240-1708275938-4037827222-500\Environment\COMPlus_ETWEnabled0NAS\Administrator
13241300x8000000000000000280567Microsoft-Windows-Sysmon/Operationalar-win.nas.domain-SetValue2024-12-08 16:41:56.578{38b9f94a-cc54-6755-b598-000000002f03}10796C:\Windows\system32\reg.exeHKLM\System\CurrentControlSet\Control\Session Manager\Environment\COMPlus_ETWEnabled0NAS\Administrator
13241300x8000000000000000279695Microsoft-Windows-Sysmon/Operationalar-win.nas.domain-SetValue2024-12-08 16:05:24.309{38b9f94a-c295-6755-6497-000000002f03}10732C:\Windows\system32\WindowsPowerShell\v1.0\PowerShell.exeHKLM\System\CurrentControlSet\Control\Session Manager\Environment\COMPlus_ETWEnabled0NAS\Administrator
13241300x8000000000000000279686Microsoft-Windows-Sysmon/Operationalar-win.nas.domain-SetValue2024-12-08 16:05:05.764{38b9f94a-c3b1-6755-9197-000000002f03}6004C:\Windows\system32\reg.exeHKLM\System\CurrentControlSet\Control\Session Manager\Environment\COMPlus_ETWEnabled0NAS\Administrator
13241300x8000000000000000279581Microsoft-Windows-Sysmon/Operationalar-win.nas.domain-SetValue2024-12-08 16:00:41.926{38b9f94a-c295-6755-6497-000000002f03}10732C:\Windows\system32\WindowsPowerShell\v1.0\PowerShell.exeHKU\S-1-5-21-2591002240-1708275938-4037827222-500\Environment\COMPlus_ETWEnabled0NAS\Administrator
13241300x8000000000000000279472Microsoft-Windows-Sysmon/Operationalar-win.nas.domain-SetValue2024-12-08 15:57:28.867{38b9f94a-c1e5-6755-4e97-000000002f03}11228C:\Windows\system32\reg.exeHKU\S-1-5-21-2591002240-1708275938-4037827222-500\Environment\COMPlus_ETWEnabled0NAS\Administrator
13241300x8000000000000000278791Microsoft-Windows-Sysmon/Operationalar-win.nas.domainSuspicious,ImageBeginWithBackslashSetValue2024-12-08 14:46:21.069{38b9f94a-90c2-6750-e40c-000000002f03}4032C:\Windows\regedit.exeHKU\S-1-5-21-2591002240-1708275938-4037827222-500\Environment\COMPlus_ETWEnabled0NAS\Administrator
13241300x8000000000000000278762Microsoft-Windows-Sysmon/Operationalar-win.nas.domainSuspicious,ImageBeginWithBackslashSetValue2024-12-08 14:43:14.872{38b9f94a-90c2-6750-e40c-000000002f03}4032C:\Windows\regedit.exeHKLM\System\CurrentControlSet\Control\Session Manager\Environment\COMPlus_ETWEnabled0NAS\Administrator
13241300x8000000000000000278739Microsoft-Windows-Sysmon/Operationalar-win.nas.domainSuspicious,ImageBeginWithBackslashSetValue2024-12-08 14:40:10.057{38b9f94a-90c2-6750-e40c-000000002f03}4032C:\Windows\regedit.exeHKU\S-1-5-21-2591002240-1708275938-4037827222-500\Environment\COMPlus_ETWEnabledDWORD (0x00000000)NAS\Administrator
13241300x8000000000000000278725Microsoft-Windows-Sysmon/Operationalar-win.nas.domainSuspicious,ImageBeginWithBackslashSetValue2024-12-08 14:38:49.307{38b9f94a-90c2-6750-e40c-000000002f03}4032C:\Windows\regedit.exeHKU\S-1-5-21-2591002240-1708275938-4037827222-500\Environment\COMPlus_ETWEnabled0NAS\Administrator