Hello Boopathi Subramaniam,
Thank you for posting in our Q&A forum.
You can try to enable audit policy via local group policy and audit permissions on this specific registry key.
Tip: This event generates when a registry key value was modified. It doesn’t generate when a registry key was modified.
Here are the detailed steps:
For enabling audit policy via local group policy:
Legacy audit policy:
Computer Configuration\Windows settings\security settings\local policies\audit policy
Audit object access– Success and Failure
Or use advanced audit policies (advanced audit policies will overwrite all legacy audit policies by default):
Computer Configuration\Windows settings\security settings\Advanced Audit Policy Configuration\Audit object access\Audit Registry– Success and Failure
For setting audit permissions on this specific registry key:
1.Find this specific registry key and set as below.
- Set Auditing entry for control.
Principal: Everyone.
Type: All
Applies to: This key and subkeys.
Full control for Basic permission and advanced permissions.
https://learn.microsoft.com/en-us/windows/security/threat-protection/auditing/event-4657
Hope the information above is helpful. If you have any question or concern, please feel free to let us know.
Best Regards,
Daisy Zhou
============================================
If the Answer is helpful, please click "Accept Answer" and upvote it.