Sysmon Event ID 15: Alternate data stream created
- Event ID
- 15
- Channel
- Microsoft-Windows-Sysmon/Operational
- Provider
- Microsoft-Windows-Sysmon
- Log file
- Microsoft-Windows-Sysmon%4Operational.evtx
- Category
- Files
- Default logging
- Needs configuration
What event 15 means
Sysmon event 15 fires when a named (alternate) data stream is created on a file. It records the file, a hash, and for small text streams the stream contents.
The most common case is the Zone.Identifier stream that browsers and mail clients attach to downloads — the mark of the web. Its contents (ZoneId=3 for the Internet zone, and on recent Windows versions ReferrerUrl and HostUrl) tell you where a file came from, even after the browser history is gone.
Attackers also hide payloads in alternate streams (file.txt:payload.exe) and execute them from there.
When it is logged
Sysmon installed; filter with <FileCreateStreamHash> rules in the configuration.
Key fields
| Field | What it tells you |
|---|---|
| ProcessGuid | Process that created the stream. |
| Image | Executable that created the stream, typically a browser or mail client for downloads. |
| TargetFilename | File and stream name, e.g. C:\Users\bob\Downloads\invoice.iso:Zone.Identifier. |
| CreationUtcTime | Creation time of the file. |
| Hash | Hashes of the file content, per HashAlgorithms. |
| Contents | Text contents of small streams such as Zone.Identifier (ZoneId, ReferrerUrl, HostUrl). Empty for larger or binary streams. |
| User | Account of the process (newer Sysmon versions). |
Common benign sources
- Browsers and Outlook adding Zone.Identifier to every download or saved attachment.
- Some backup, sync and security products using named streams for metadata.
What attackers do that produces it
- Downloads of ISO, ZIP, LNK or script files from unknown hosts, visible in HostUrl.
- Payloads hidden in a named stream of an innocuous file and executed from it.
Investigation tips
- Read Contents for HostUrl and ReferrerUrl to identify the delivery source.
- Pivot on TargetFilename to event 1 to see whether the downloaded file was run.
- Treat non-Zone.Identifier streams containing executable content as suspicious.
MITRE ATT&CK techniques
MITRE ATT&CK v19.2. Technique and tactic names are MITRE's.
Sigma rules for this event
9 SigmaHQ detection rules (release r2026-07-01) target this event.
- High · 6
- Medium · 3
- HighExports Registry Key To an Alternate Data StreamRule by Oddvar Moe, Sander Wiebing, oscd.community, SigmaHQ, DRL 1.1
- HighHackTool Named File Stream CreatedRule by Florian Roth (Nextron Systems), SigmaHQ, DRL 1.1
- HighPotential Suspicious Winget Package InstallationRule by Nasreddine Bencherchali (Nextron Systems), SigmaHQ, DRL 1.1
- HighPotentially Suspicious File Download From ZIP TLDRule by Florian Roth (Nextron Systems), SigmaHQ, DRL 1.1
- HighSuspicious File Download From File Sharing Websites - File StreamRule by Florian Roth (Nextron Systems), SigmaHQ, DRL 1.1
- HighUnusual File Download from Direct IP AddressRule by Nasreddine Bencherchali (Nextron Systems), Florian Roth (Nextron Systems), SigmaHQ, DRL 1.1
- MediumCreation Of a Suspicious ADS File Outside a Browser DownloadRule by frack113, SigmaHQ, DRL 1.1
- MediumHidden Executable In NTFS Alternate Data StreamRule by Florian Roth (Nextron Systems), @0xrawsec, SigmaHQ, DRL 1.1
- MediumUnusual File Download From File Sharing Websites - File StreamRule by Florian Roth (Nextron Systems), SigmaHQ, DRL 1.1
Rules by their named authors, published by SigmaHQ under the Detection Rule License (DRL) 1.1.
Run these rules on your logs
Drop a .evtx file into the viewer: all 2,395 bundled SigmaHQ rules run locally in your browser. Nothing is uploaded.