Windows Sysmon FileExecutableDetected (Event ID 29) Alerts on New Executable Files

Alerts on any Sysmon Event ID 29 indicating a new monitored executable file was created on Windows.

FreeReviewedSigma · Medium · v1
Product
windows
Service
sysmon
Author
frack113 (SigmaHQ), DRL 1.1
Published
2023-07-20
Updated
2026-07-30

What it detects

This rule fires for every Sysmon FileExecutableDetected event (Event ID 29), which occurs when a monitored executable (PE) file is created. Attackers can leverage executable drops and staging to move payloads onto disk before execution, so alerting on these creations helps identify suspicious on-disk activity early. The detection relies on Sysmon event telemetry from the Windows Sysmon service, specifically the EventID value for FileExecutableDetected.

Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.