Windows Alternate Data Stream Creation: Suspicious Zone.Identifier ADS Outside Browser Download

Flags suspicious creation of :Zone.Identifier ADS streams (ZoneTransfer/ZoneId=3) on file types outside typical browsers.

FreeReviewedSigma · Medium · v2
Product
windows
Category
create_stream_hash
Author
frack113 (SigmaHQ), DRL 1.1
Published
2022-10-22
Updated
2026-07-31

What it detects

This rule identifies creation of an Alternate Data Stream (ADS) marked with the [ZoneTransfer] header and ZoneId=3, specifically targeting a TargetFilename ending in :Zone.Identifier for file types commonly abused for execution. Attackers can use ADS to attach a Zone.Identifier stream to masquerade as downloaded content or influence how Windows and security checks treat files. The detection relies on Windows telemetry that records stream creation events, including stream contents, the target filename, and the originating process image for browser exclusions.

Changelog

v2
  1. v2
    Candidate ingested via manual entry.2026-07-31
  2. v1
    No changelog recorded for this version.2026-07-30

Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.