Registry discovery atomics can execute successfully while Rustinel records their process/script context without a direct event describing which registry key or value was queried.
Examples at upstream Atomic revision 388942adbd9641f4dfdcf079d7efe9a75ec0ac43: installed-application discovery using Get-ItemProperty, and reg query discovery commands in the reviewed Windows batch.
This is an explicit collector limitation rather than a confirmed event drop: src/sensor/windows/etw/routing.rs filters registry query/enumeration events out and routes supported mutations separately. Full PowerShell script-block logging exposes the command content, but does not prove an individual read occurred or returned a value.
Add optional registry query/enumeration telemetry for capture and behavioral audits. Keep reads semantically distinct from writes, expose key/value/operation/status and provider-validated actor context where available, and make volume/sensitive-field controls explicit. Identify the current provider schemas before implementing routing; do not reuse classic event numbers without verifying them.
Acceptance: a native query fixture against a synthetic key establishes the read independently; capture records the query without classifying it as a registry modification; disabled collection is reported as unsupported, and enabled collection has loss/decoder-health checks.
Related: #420, #641, #486. File-read collection in #551 is a separate event family.
Default (2026-09-30)
Collection is off by default.
Registry query and enumeration events are far more frequent than writes, so their volume is measured on lab-windows before any default changes.
Registry discovery atomics can execute successfully while Rustinel records their process/script context without a direct event describing which registry key or value was queried.
Examples at upstream Atomic revision
388942adbd9641f4dfdcf079d7efe9a75ec0ac43: installed-application discovery usingGet-ItemProperty, andreg querydiscovery commands in the reviewed Windows batch.This is an explicit collector limitation rather than a confirmed event drop:
src/sensor/windows/etw/routing.rsfilters registry query/enumeration events out and routes supported mutations separately. Full PowerShell script-block logging exposes the command content, but does not prove an individual read occurred or returned a value.Add optional registry query/enumeration telemetry for capture and behavioral audits. Keep reads semantically distinct from writes, expose key/value/operation/status and provider-validated actor context where available, and make volume/sensitive-field controls explicit. Identify the current provider schemas before implementing routing; do not reuse classic event numbers without verifying them.
Acceptance: a native query fixture against a synthetic key establishes the read independently; capture records the query without classifying it as a registry modification; disabled collection is reported as unsupported, and enabled collection has loss/decoder-health checks.
Related: #420, #641, #486. File-read collection in #551 is a separate event family.
Default (2026-09-30)
Collection is off by default.
Registry query and enumeration events are far more frequent than writes, so their volume is measured on lab-windows before any default changes.