Windows Sysmon FileExecutableDetected (Event ID 29) Alerts on New Executable Files
Alerts on any Sysmon Event ID 29 indicating a new monitored executable file was created on Windows.
FreeReviewedSigma · Medium · v1
- Product
- windows
- Service
- sysmon
- Author
- frack113 (SigmaHQ), DRL 1.1
- Published
- 2023-07-20
- Updated
- 2026-07-30
What it detects
This rule fires for every Sysmon FileExecutableDetected event (Event ID 29), which occurs when a monitored executable (PE) file is created. Attackers can leverage executable drops and staging to move payloads onto disk before execution, so alerting on these creations helps identify suspicious on-disk activity early. The detection relies on Sysmon event telemetry from the Windows Sysmon service, specifically the EventID value for FileExecutableDetected.
Reporting behind it
Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.
windows-sysmon-fileexecutabledetected-event-id-29-alerts-on-new-executable-files-693a44e9
title: Windows Sysmon FileExecutableDetected (Event ID 29) Alerts on New Executable Files
id: 454b0c59-e87d-4e9d-9049-9c0854ee1b57
status: test
description: This rule fires for every Sysmon FileExecutableDetected event (Event ID 29), which occurs when a monitored executable (PE) file is created. Attackers can leverage executable drops and staging to move payloads onto disk before execution, so alerting on these creations helps identify suspicious on-disk activity early. The detection relies on Sysmon event telemetry from the Windows Sysmon service, specifically the EventID value for FileExecutableDetected.
references:
- https://learn.microsoft.com/en-us/sysinternals/downloads/sysmon
- https://medium.com/@olafhartong/sysmon-15-0-file-executable-detected-40fd64349f36
- https://github.com/SigmaHQ/sigma/blob/master/rules/windows/sysmon/sysmon_file_executable_detected.yml
author: frack113, Huntrule Team
date: 2023-07-20
tags:
- attack.defense-impairment
logsource:
product: windows
service: sysmon
detection:
selection:
EventID: 29
condition: selection
falsepositives:
- Unlikely
level: medium
license: DRL-1.1
related:
- id: 693a44e9-7f26-4cb6-b787-214867672d3a
type: derived