Skip to content
Sysmon

Sysmon Event ID 27: Executable file blocked

FileBlockExecutableSysmon event 27 fires when Sysmon blocks the creation of an executable (PE) file matching its rules. A preventive control added in Sysmon 14.0.
27
Event ID
27
Channel
Microsoft-Windows-Sysmon/Operational
Provider
Microsoft-Windows-Sysmon
Log file
Microsoft-Windows-Sysmon%4Operational.evtx
Category
Files
Default logging
Needs configuration

What event 27 means

Sysmon event 27 is generated when Sysmon detects and blocks a process writing a PE executable file that matches a <FileBlockExecutable> rule. Unlike most Sysmon events, this one reflects an action: the file is not allowed to stay on disk.

Typical rules block executables written to user profile, temp or download folders by browsers, mail clients and script hosts. Each record means something tried to drop a binary; the question is whether it was a user download or a payload.

When it is logged

Audit policy / configuration

Sysmon 14.0 or later with a <FileBlockExecutable> rule in the configuration.

Blocking can break legitimate installers and updaters that write executables to the targeted folders; test rules before deploying them.

Key fields

FieldWhat it tells you
ProcessGuidProcess that tried to write the executable.
ImageExecutable that tried to write the file.
UserAccount of the process.
TargetFilenamePath of the blocked executable.
HashesHashes of the blocked file; use them for reputation lookups.

Common benign sources

  • Users downloading legitimate installers into blocked folders.
  • Software updaters writing new binaries to user-profile locations.

What attackers do that produces it

  • A malicious document or script host trying to drop a payload EXE or DLL into %TEMP% or %APPDATA%.
  • Tools copied to a host for lateral movement or privilege escalation being stopped on write.

Investigation tips

  • Pivot on ProcessGuid to event 1 to see what chain tried to drop the file.
  • Look up Hashes; a known-bad hash confirms an intrusion attempt even though it was blocked.
  • Check whether the attacker retried with another path or file type (events 11, 29).

MITRE ATT&CK techniques

TechniqueTactics
T1105 Ingress Tool TransferCommand and Control
T1204.002 User Execution: Malicious FileExecution
T1570 Lateral Tool TransferLateral Movement

MITRE ATT&CK v19.2. Technique and tactic names are MITRE's.

Sigma rules for this event

1 SigmaHQ detection rules (release r2026-07-01) target this event.

  • High · 1

Rules by their named authors, published by SigmaHQ under the Detection Rule License (DRL) 1.1.

Run these rules on your logs

Drop a .evtx file into the viewer: all 2,395 bundled SigmaHQ rules run locally in your browser. Nothing is uploaded.

Sources and further reading