Skip to content

feat(windows-etw): add configurable registry query and enumeration telemetry #669

Description

@Karib0u

Registry discovery atomics can execute successfully while Rustinel records their process/script context without a direct event describing which registry key or value was queried.

Examples at upstream Atomic revision 388942adbd9641f4dfdcf079d7efe9a75ec0ac43: installed-application discovery using Get-ItemProperty, and reg query discovery commands in the reviewed Windows batch.

This is an explicit collector limitation rather than a confirmed event drop: src/sensor/windows/etw/routing.rs filters registry query/enumeration events out and routes supported mutations separately. Full PowerShell script-block logging exposes the command content, but does not prove an individual read occurred or returned a value.

Add optional registry query/enumeration telemetry for capture and behavioral audits. Keep reads semantically distinct from writes, expose key/value/operation/status and provider-validated actor context where available, and make volume/sensitive-field controls explicit. Identify the current provider schemas before implementing routing; do not reuse classic event numbers without verifying them.

Acceptance: a native query fixture against a synthetic key establishes the read independently; capture records the query without classifying it as a registry modification; disabled collection is reported as unsupported, and enabled collection has loss/decoder-health checks.

Related: #420, #641, #486. File-read collection in #551 is a separate event family.

Default (2026-09-30)

Collection is off by default.
Registry query and enumeration events are far more frequent than writes, so their volume is measured on lab-windows before any default changes.

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    enhancementNew feature or requestsensorSensor and telemetry workwindowsWindows support

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions