Sysmon FileBlockExecutable event: blocked executable execution attempts on Windows

Alerts when Sysmon blocks an attempted executable execution due to FileBlockExecutable policy violations.

FreeReviewedSigma · High · v1
Product
windows
Service
sysmon
Author
Nasreddine Bencherchali (Nextron Systems) (SigmaHQ), DRL 1.1
Published
2022-08-16
Updated
2026-07-30

What it detects

This rule triggers on any Sysmon FileBlockExecutable event (EventID 27), indicating an attempt to execute an executable that violated the configured block policy. Attackers may rely on execution of unauthorized binaries or dropped malware, so blocked execution events are a strong signal of defense-impairment controls working as intended. It relies on Sysmon process/file blocking telemetry emitted by Windows (Sysmon service).

Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.