Sysmon Event ID 27: Executable file blocked
- Event ID
- 27
- Channel
- Microsoft-Windows-Sysmon/Operational
- Provider
- Microsoft-Windows-Sysmon
- Log file
- Microsoft-Windows-Sysmon%4Operational.evtx
- Category
- Files
- Default logging
- Needs configuration
What event 27 means
Sysmon event 27 is generated when Sysmon detects and blocks a process writing a PE executable file that matches a <FileBlockExecutable> rule. Unlike most Sysmon events, this one reflects an action: the file is not allowed to stay on disk.
Typical rules block executables written to user profile, temp or download folders by browsers, mail clients and script hosts. Each record means something tried to drop a binary; the question is whether it was a user download or a payload.
When it is logged
Sysmon 14.0 or later with a <FileBlockExecutable> rule in the configuration.
Blocking can break legitimate installers and updaters that write executables to the targeted folders; test rules before deploying them.
Key fields
| Field | What it tells you |
|---|---|
| ProcessGuid | Process that tried to write the executable. |
| Image | Executable that tried to write the file. |
| User | Account of the process. |
| TargetFilename | Path of the blocked executable. |
| Hashes | Hashes of the blocked file; use them for reputation lookups. |
Common benign sources
- Users downloading legitimate installers into blocked folders.
- Software updaters writing new binaries to user-profile locations.
What attackers do that produces it
- A malicious document or script host trying to drop a payload EXE or DLL into
%TEMP%or%APPDATA%. - Tools copied to a host for lateral movement or privilege escalation being stopped on write.
Investigation tips
- Pivot on ProcessGuid to event 1 to see what chain tried to drop the file.
- Look up Hashes; a known-bad hash confirms an intrusion attempt even though it was blocked.
- Check whether the attacker retried with another path or file type (events 11, 29).
MITRE ATT&CK techniques
MITRE ATT&CK v19.2. Technique and tactic names are MITRE's.
Sigma rules for this event
1 SigmaHQ detection rules (release r2026-07-01) target this event.
- High · 1
- HighSysmon Blocked ExecutableRule by Nasreddine Bencherchali (Nextron Systems), SigmaHQ, DRL 1.1
Rules by their named authors, published by SigmaHQ under the Detection Rule License (DRL) 1.1.
Run these rules on your logs
Drop a .evtx file into the viewer: all 2,395 bundled SigmaHQ rules run locally in your browser. Nothing is uploaded.