Suspicious Registry Access by System Utilities
This rule detects an unusually high number of registry access events initiated by common Windows system utilities such as 'reg.exe', 'regsvcs.exe', or 'regasm.exe' within a one-hour window. A count of 5 or more registry access events from these processes is considered suspicious and may indicate malicious activity like persistence, defense evasion, or privilege escalation through registry modification.
Microsoft Sentinel (KQL)

