Sysmon Event ID 11: File created
- Event ID
- 11
- Channel
- Microsoft-Windows-Sysmon/Operational
- Provider
- Microsoft-Windows-Sysmon
- Log file
- Microsoft-Windows-Sysmon%4Operational.evtx
- Category
- Files
- Default logging
- Needs configuration
What event 11 means
Sysmon event 11 records file creation or overwrite, naming the file (TargetFilename) and the process that wrote it. It is the Sysmon answer to "where did this file come from?".
Useful targets are autostart locations (Startup folders, System32\Tasks), download and temp folders, script and executable extensions, and dump files such as lsass.dmp. CreationUtcTime is the file's creation timestamp; for an overwritten file it can be older than the event time.
File activity is heavy on any system, so configurations include specific folders and extensions rather than logging everything.
When it is logged
Sysmon installed; filter with <FileCreate> rules in the configuration (include folders and extensions of interest).
Key fields
| Field | What it tells you |
|---|---|
| ProcessGuid | Process that wrote the file; pivot to its event 1. |
| Image | Executable that wrote the file. |
| TargetFilename | Full path of the created file. |
| CreationUtcTime | Creation time of the file (can predate UtcTime when an existing file is overwritten). |
| User | Account of the process (newer Sysmon versions). |
Common benign sources
- Browsers writing downloads, installers writing to Program Files, updaters replacing binaries.
- Office and Windows writing temp and cache files.
What attackers do that produces it
- Payloads dropped in
%TEMP%,%APPDATA%,ProgramDataorC:\Users\Public. - Persistence files in
...\Start Menu\Programs\Startupor new task XML inC:\Windows\System32\Tasks. - Memory dumps such as
lsass.dmpwritten by ProcDump, Task Manager orrundll32.exe. - Tools copied to
C:\Windowsvia admin shares bySystemduring PsExec-style lateral movement.
Investigation tips
- Pivot on ProcessGuid to event 1 to see which process and parent wrote the file.
- Look for a later event 1 whose Image equals TargetFilename — the dropped file was executed.
- Check event 15 for the Zone.Identifier stream on downloaded files to get the source URL.
MITRE ATT&CK techniques
MITRE ATT&CK v19.2. Technique and tactic names are MITRE's.
Sigma rules for this event
165 SigmaHQ detection rules (release r2026-07-01) target this event. Showing the 25 highest-severity rules.
- Critical · 7
- High · 89
- Medium · 60
- Low · 9
- CriticalHackTool - Dumpert Process Dumper Default FileRule by Florian Roth (Nextron Systems), SigmaHQ, DRL 1.1
- CriticalHackTool - Inveigh Execution ArtefactsRule by Nasreddine Bencherchali (Nextron Systems), SigmaHQ, DRL 1.1
- CriticalHackTool - Mimikatz Kirbi File CreationRule by Florian Roth (Nextron Systems), David ANDRE, SigmaHQ, DRL 1.1
- CriticalHackTool - QuarksPwDump Dump FileRule by Florian Roth (Nextron Systems), SigmaHQ, DRL 1.1
- CriticalPotential DCOM InternetExplorer.Application DLL HijackRule by Roberto Rodriguez @Cyb3rWard0g, Open Threat Research (OTR), wagga, SigmaHQ, DRL 1.1
- CriticalWmiexec Default Output FileRule by Nasreddine Bencherchali (Nextron Systems), SigmaHQ, DRL 1.1
- CriticalWmiprvse Wbemcomn DLL Hijack - FileRule by Roberto Rodriguez (Cyb3rWard0g), OTR (Open Threat Research), SigmaHQ, DRL 1.1
- High.RDP File Created By Uncommon ApplicationRule by Nasreddine Bencherchali (Nextron Systems), SigmaHQ, DRL 1.1
- HighAdwind RAT / JRAT File ArtifactRule by Florian Roth (Nextron Systems), Tom Ueltschi, Jonhnathan Ribeiro, oscd.community, SigmaHQ, DRL 1.1
- HighBloodHound Collection FilesRule by C.J. May, SigmaHQ, DRL 1.1
- HighCreation Exe for Service with Unquoted PathRule by frack113, SigmaHQ, DRL 1.1
- HighCred Dump Tools Dropped FilesRule by Teymur Kheirkhabarov, oscd.community, SigmaHQ, DRL 1.1
- HighDLL Search Order Hijackig Via Additional Space in PathRule by frack113, Nasreddine Bencherchali (Nextron Systems), SigmaHQ, DRL 1.1
- HighDPAPI Backup Keys And Certificate Export Activity IOCRule by Nounou Mbeiri, Nasreddine Bencherchali (Nextron Systems), SigmaHQ, DRL 1.1
- HighFile Creation In Suspicious Directory By Msdt.EXERule by Vadim Varganov, Florian Roth (Nextron Systems), SigmaHQ, DRL 1.1
- HighFile With Uncommon Extension Created By An Office ApplicationRule by Vadim Khrykov (ThreatIntel), Cyb3rEng (Rule), Nasreddine Bencherchali (Nextron Systems), SigmaHQ, DRL 1.1
- HighHackTool - CrackMapExec File IndicatorsRule by Nasreddine Bencherchali (Nextron Systems), SigmaHQ, DRL 1.1
- HighHackTool - Impacket File IndicatorsRule by The DFIR Report, IrishDeath, SigmaHQ, DRL 1.1
- HighHackTool - NetExec File IndicatorsRule by Swachchhanda Shrawan Poudel (Nextron Systems), SigmaHQ, DRL 1.1
- HighHackTool - NPPSpy Hacktool UsageRule by Florian Roth (Nextron Systems), SigmaHQ, DRL 1.1
- HighHackTool - Potential Remote Credential Dumping Activity Via CrackMapExec Or Impacket-SecretsdumpRule by SecurityAura, SigmaHQ, DRL 1.1
- HighHackTool - Powerup Write Hijack DLLRule by Subhash Popuri (@pbssubhash), SigmaHQ, DRL 1.1
- HighHackTool - RemoteKrbRelay SMB Relay Secrets Dump Module IndicatorsRule by Nasreddine Bencherchali (Nextron Systems), SigmaHQ, DRL 1.1
- HighHackTool - SafetyKatz Dump IndicatorRule by Markus Neis, SigmaHQ, DRL 1.1
- HighHackTool - Typical HiveNightmare SAM File ExportRule by Florian Roth (Nextron Systems), SigmaHQ, DRL 1.1
Rules by their named authors, published by SigmaHQ under the Detection Rule License (DRL) 1.1.
Run these rules on your logs
Drop a .evtx file into the viewer: all 2,395 bundled SigmaHQ rules run locally in your browser. Nothing is uploaded.