Hey Ivo,
So, Sysmon ain’t great with Alternate Data Streams (ADS), like that zone.identifier
thing when u unblock downloads. It just doesn’t track ADS deletions well, ‘cause it’s mostly focused on regular files, not the extra streams. If u need to monitor that stuff, u might wanna use a PowerShell script or some other tool to check for changes in the ADS and log it manually. Like, u can make a script that sees if the zone.identifier
is gone and then logs it somewhere. Sysmon’s awesome, but it’s kinda dumb with ADS, so u gotta work around it.
Hope that makes sense,
Alex