registryKeyEvidence resource type

Namespace: microsoft.graph.security

A registry key that is reported in the alert as evidence.

Inherits from alertEvidence.

Properties

Property Type Description
registryHive String Registry hive of the key that the recorded action was applied to.
registryKey String Registry key that the recorded action was applied to.

Relationships

None.

JSON representation

The following JSON representation shows the resource type.

{
  "@odata.type": "#microsoft.graph.security.registryKeyEvidence",
  "createdDateTime": "String (timestamp)",
  "verdict": "String",
  "remediationStatus": "String",
  "remediationStatusDetails": "String",
  "roles": [
    "String"
  ],
  "tags": [
    "String"
  ],
  "registryKey": "String",
  "registryHive": "String"
}