Event ID 29
Sysmon detects the creation of a new executable fileSource:
Microsoft-Windows-Sysmon
File Executable Detected:
RuleName: %1!s!
UtcTime: %2!s!
ProcessGuid: %3!s!
ProcessId: %4!s!
User: %5!s!
Image: %6!s!
TargetFilename: %7!s!
Hashes: %8!s!This event is generated when Sysmon detects the creation of a new executable file (PE format).
LEFT/RIGHT arrow keys for navigation
Back to List