Skip to content
Sysmon

Sysmon Event ID 15: Alternate data stream created

FileCreateStreamHashSysmon event 15 logs a named NTFS stream being created, such as the Zone.Identifier mark of the web on downloads. Reveals download origins and ADS use.
15
Event ID
15
Channel
Microsoft-Windows-Sysmon/Operational
Provider
Microsoft-Windows-Sysmon
Log file
Microsoft-Windows-Sysmon%4Operational.evtx
Category
Files
Default logging
Needs configuration

What event 15 means

Sysmon event 15 fires when a named (alternate) data stream is created on a file. It records the file, a hash, and for small text streams the stream contents.

The most common case is the Zone.Identifier stream that browsers and mail clients attach to downloads — the mark of the web. Its contents (ZoneId=3 for the Internet zone, and on recent Windows versions ReferrerUrl and HostUrl) tell you where a file came from, even after the browser history is gone.

Attackers also hide payloads in alternate streams (file.txt:payload.exe) and execute them from there.

When it is logged

Audit policy / configuration

Sysmon installed; filter with <FileCreateStreamHash> rules in the configuration.

Key fields

FieldWhat it tells you
ProcessGuidProcess that created the stream.
ImageExecutable that created the stream, typically a browser or mail client for downloads.
TargetFilenameFile and stream name, e.g. C:\Users\bob\Downloads\invoice.iso:Zone.Identifier.
CreationUtcTimeCreation time of the file.
HashHashes of the file content, per HashAlgorithms.
ContentsText contents of small streams such as Zone.Identifier (ZoneId, ReferrerUrl, HostUrl). Empty for larger or binary streams.
UserAccount of the process (newer Sysmon versions).

Common benign sources

  • Browsers and Outlook adding Zone.Identifier to every download or saved attachment.
  • Some backup, sync and security products using named streams for metadata.

What attackers do that produces it

  • Downloads of ISO, ZIP, LNK or script files from unknown hosts, visible in HostUrl.
  • Payloads hidden in a named stream of an innocuous file and executed from it.

Investigation tips

  • Read Contents for HostUrl and ReferrerUrl to identify the delivery source.
  • Pivot on TargetFilename to event 1 to see whether the downloaded file was run.
  • Treat non-Zone.Identifier streams containing executable content as suspicious.

MITRE ATT&CK techniques

TechniqueTactics
T1564.004 Hide Artifacts: NTFS File AttributesStealth
T1105 Ingress Tool TransferCommand and Control
T1553.005 Subvert Trust Controls: Mark-of-the-Web BypassDefense Impairment

MITRE ATT&CK v19.2. Technique and tactic names are MITRE's.

Sigma rules for this event

9 SigmaHQ detection rules (release r2026-07-01) target this event.

  • High · 6
  • Medium · 3

Rules by their named authors, published by SigmaHQ under the Detection Rule License (DRL) 1.1.

Run these rules on your logs

Drop a .evtx file into the viewer: all 2,395 bundled SigmaHQ rules run locally in your browser. Nothing is uploaded.

Sources and further reading