Sysmon Event ID 29: Executable file detected
- Event ID
- 29
- Channel
- Microsoft-Windows-Sysmon/Operational
- Provider
- Microsoft-Windows-Sysmon
- Log file
- Microsoft-Windows-Sysmon%4Operational.evtx
- Category
- Files
- Default logging
- Needs configuration
What event 29 means
Sysmon event 29 fires when Sysmon detects a new executable file being written to disk. It is the detect-only counterpart of event 27: same fields, but the file is allowed to stay.
Because Sysmon checks the file format rather than the extension, it catches executables written with misleading names such as .txt or .dat. That makes event 29 a more reliable way to track dropped binaries than event 11 filtered on .exe and .dll.
When it is logged
Sysmon 15.0 or later with a <FileExecutableDetected> rule in the configuration.
Key fields
| Field | What it tells you |
|---|---|
| ProcessGuid | Process that wrote the executable. |
| Image | Executable that wrote the file. |
| User | Account of the process. |
| TargetFilename | Path of the new executable file. Check for non-executable extensions. |
| Hashes | Hashes of the new file for reputation lookups and fleet-wide prevalence. |
Common benign sources
- Installers, Windows Update and software updaters writing binaries.
- Developers' compilers and build tools producing executables.
What attackers do that produces it
- Payloads written by Office, browsers or script hosts into user folders.
- Tools copied over SMB during lateral movement (written by
System). - PE files disguised with non-executable extensions.
Investigation tips
- Pivot on ProcessGuid to event 1 to see the writing process chain.
- Look for a later event 1 or 7 using TargetFilename — the binary was executed or loaded.
- Count Hashes across the fleet; unique binaries in user folders are worth review.
MITRE ATT&CK techniques
MITRE ATT&CK v19.2. Technique and tactic names are MITRE's.
Sigma rules for this event
2 SigmaHQ detection rules (release r2026-07-01) target this event.
- Medium · 2
- MediumPotentially Suspicious Self Extraction Directive File CreatedRule by Joseliyo Sanchez, @Joseliyo_Jstnk, SigmaHQ, DRL 1.1
- MediumSysmon File Executable Creation DetectedRule by frack113, SigmaHQ, DRL 1.1
Rules by their named authors, published by SigmaHQ under the Detection Rule License (DRL) 1.1.
Run these rules on your logs
Drop a .evtx file into the viewer: all 2,395 bundled SigmaHQ rules run locally in your browser. Nothing is uploaded.