Skip to content
Sysmon

Sysmon Event ID 11: File created

FileCreateSysmon event 11 logs a file being created or overwritten and the process that wrote it. Key for dropped payloads, persistence folders and dump files.
11
Event ID
11
Channel
Microsoft-Windows-Sysmon/Operational
Provider
Microsoft-Windows-Sysmon
Log file
Microsoft-Windows-Sysmon%4Operational.evtx
Category
Files
Default logging
Needs configuration

What event 11 means

Sysmon event 11 records file creation or overwrite, naming the file (TargetFilename) and the process that wrote it. It is the Sysmon answer to "where did this file come from?".

Useful targets are autostart locations (Startup folders, System32\Tasks), download and temp folders, script and executable extensions, and dump files such as lsass.dmp. CreationUtcTime is the file's creation timestamp; for an overwritten file it can be older than the event time.

File activity is heavy on any system, so configurations include specific folders and extensions rather than logging everything.

When it is logged

Audit policy / configuration

Sysmon installed; filter with <FileCreate> rules in the configuration (include folders and extensions of interest).

Key fields

FieldWhat it tells you
ProcessGuidProcess that wrote the file; pivot to its event 1.
ImageExecutable that wrote the file.
TargetFilenameFull path of the created file.
CreationUtcTimeCreation time of the file (can predate UtcTime when an existing file is overwritten).
UserAccount of the process (newer Sysmon versions).

Common benign sources

  • Browsers writing downloads, installers writing to Program Files, updaters replacing binaries.
  • Office and Windows writing temp and cache files.

What attackers do that produces it

  • Payloads dropped in %TEMP%, %APPDATA%, ProgramData or C:\Users\Public.
  • Persistence files in ...\Start Menu\Programs\Startup or new task XML in C:\Windows\System32\Tasks.
  • Memory dumps such as lsass.dmp written by ProcDump, Task Manager or rundll32.exe.
  • Tools copied to C:\Windows via admin shares by System during PsExec-style lateral movement.

Investigation tips

  • Pivot on ProcessGuid to event 1 to see which process and parent wrote the file.
  • Look for a later event 1 whose Image equals TargetFilename — the dropped file was executed.
  • Check event 15 for the Zone.Identifier stream on downloaded files to get the source URL.

MITRE ATT&CK techniques

TechniqueTactics
T1105 Ingress Tool TransferCommand and Control
T1547.001 Boot or Logon Autostart Execution: Registry Run Keys / Startup FolderPersistence, Privilege Escalation
T1570 Lateral Tool TransferLateral Movement
T1003.001 OS Credential Dumping: LSASS MemoryCredential Access

MITRE ATT&CK v19.2. Technique and tactic names are MITRE's.

Sigma rules for this event

165 SigmaHQ detection rules (release r2026-07-01) target this event. Showing the 25 highest-severity rules.

  • Critical · 7
  • High · 89
  • Medium · 60
  • Low · 9

Rules by their named authors, published by SigmaHQ under the Detection Rule License (DRL) 1.1.

Run these rules on your logs

Drop a .evtx file into the viewer: all 2,395 bundled SigmaHQ rules run locally in your browser. Nothing is uploaded.

Sources and further reading