Sysmon unable to handle removal of Alternate data stream

Delver, Ivo 0 Reputation points
2025-02-25T09:45:53.6933333+00:00

Hi,

I'm currently testing sysmon 15.15 with the configuration from (Olaf Hartong) sysmonconfig-with-filedelete.xml and we came across a issue with unblocking downloads (zone.identifier alternate data stream). Is this a problem on how sysmon handles file deletes when the file is a alternate data stream?

Thanks,

Ivo

Sysinternals
Sysinternals
Advanced system utilities to manage, troubleshoot, and diagnose Windows and Linux systems and applications.
1,208 questions
0 comments No comments
{count} votes

1 answer

Sort by: Most helpful
  1. Alex Burlachenko 1,755 Reputation points
    2025-02-25T09:54:50.36+00:00

    Hey Ivo,

    So, Sysmon ain’t great with Alternate Data Streams (ADS), like that zone.identifier thing when u unblock downloads. It just doesn’t track ADS deletions well, ‘cause it’s mostly focused on regular files, not the extra streams. If u need to monitor that stuff, u might wanna use a PowerShell script or some other tool to check for changes in the ADS and log it manually. Like, u can make a script that sees if the zone.identifier is gone and then logs it somewhere. Sysmon’s awesome, but it’s kinda dumb with ADS, so u gotta work around it.

    Hope that makes sense,

    Alex

    0 comments No comments

Your answer

Answers can be marked as Accepted Answers by the question author, which helps users to know the answer solved the author's problem.