You can see who has remote registry access on your server with the ACL on that registry key :

(Get-Acl -Path HKLM:SYSTEMCurrentControlSetControlSecurePipeServerswinreg).Access | Format-Table -AutoSize


