Skip to content
Sysmon

Sysmon Event ID 29: Executable file detected

FileExecutableDetectedSysmon event 29 logs the creation of a new executable (PE) file, with hashes, without blocking it. Added in Sysmon 15.0; ideal for tracking dropped binaries.
29
Event ID
29
Channel
Microsoft-Windows-Sysmon/Operational
Provider
Microsoft-Windows-Sysmon
Log file
Microsoft-Windows-Sysmon%4Operational.evtx
Category
Files
Default logging
Needs configuration

What event 29 means

Sysmon event 29 fires when Sysmon detects a new executable file being written to disk. It is the detect-only counterpart of event 27: same fields, but the file is allowed to stay.

Because Sysmon checks the file format rather than the extension, it catches executables written with misleading names such as .txt or .dat. That makes event 29 a more reliable way to track dropped binaries than event 11 filtered on .exe and .dll.

When it is logged

Audit policy / configuration

Sysmon 15.0 or later with a <FileExecutableDetected> rule in the configuration.

Key fields

FieldWhat it tells you
ProcessGuidProcess that wrote the executable.
ImageExecutable that wrote the file.
UserAccount of the process.
TargetFilenamePath of the new executable file. Check for non-executable extensions.
HashesHashes of the new file for reputation lookups and fleet-wide prevalence.

Common benign sources

  • Installers, Windows Update and software updaters writing binaries.
  • Developers' compilers and build tools producing executables.

What attackers do that produces it

  • Payloads written by Office, browsers or script hosts into user folders.
  • Tools copied over SMB during lateral movement (written by System).
  • PE files disguised with non-executable extensions.

Investigation tips

  • Pivot on ProcessGuid to event 1 to see the writing process chain.
  • Look for a later event 1 or 7 using TargetFilename — the binary was executed or loaded.
  • Count Hashes across the fleet; unique binaries in user folders are worth review.

MITRE ATT&CK techniques

TechniqueTactics
T1105 Ingress Tool TransferCommand and Control
T1570 Lateral Tool TransferLateral Movement
T1036 MasqueradingStealth

MITRE ATT&CK v19.2. Technique and tactic names are MITRE's.

Sigma rules for this event

2 SigmaHQ detection rules (release r2026-07-01) target this event.

  • Medium · 2

Rules by their named authors, published by SigmaHQ under the Detection Rule License (DRL) 1.1.

Run these rules on your logs

Drop a .evtx file into the viewer: all 2,395 bundled SigmaHQ rules run locally in your browser. Nothing is uploaded.

Sources and further reading