Summary
We do not have a specific category for registry (for example for winlogbeat registry events)
It seems endgame and endpoint are using already an event.category = registry value, since it is not listed as an allowed value we might want to consider to add it or either find a different solution and move all our products to use it.
Motivation:
We went through https://discuss.elastic.co/t/winlogbeat-sysmon-registry-events-missing-event-category/251282 which pointed the lack of categorisation for winlogbeat sysmon events.
Summary
We do not have a specific category for registry (for example for winlogbeat registry events)
It seems endgame and endpoint are using already an
event.category = registryvalue, since it is not listed as an allowed value we might want to consider to add it or either find a different solution and move all our products to use it.Motivation:
We went through https://discuss.elastic.co/t/winlogbeat-sysmon-registry-events-missing-event-category/251282 which pointed the lack of categorisation for winlogbeat sysmon events.