Sysmon EventCode 15 records content of the primary data stream

Angelo Zinna 0 Reputation points
2025-10-15T10:43:13.4866667+00:00

I recently installed Sysmon version 15.15 on multiple Windows 11 machines using a custom configuration file with no filtering on EventCode 15.

From my understanding, EventCode 15 should be generated whenever an alternate data stream (ADS) of a file is created. However, it appears that this event is also being logged in other scenarios.

After monitoring the generated logs over the past few months, I noticed that, in certain cases, the content of the primary data stream (i.e., the actual file content, not an ADS) is included in the log when specific processes — namely MSSense.exe and chrome.exe — trigger the event. This occurs even though these processes are not expected to perform any file creation actions.

For instance:

When Microsoft Defender scans the file system, it generates numerous EventCode 15 entries containing the primary data stream of the scanned files.

Occasionally, when Chrome downloads a file, it generates two events: one corresponding to the creation of the ADS (related to the Zone.Identifier) and another showing the primary data stream of the file.

I suspect that this behavior may be related to the low-level file-handling functions used by these processes. Nevertheless, I would greatly appreciate your insights or confirmation regarding this observation.

Sysinternals
Sysinternals
Advanced system utilities to manage, troubleshoot, and diagnose Windows and Linux systems and applications.
0 comments No comments
{count} votes

Your answer

Answers can be marked as 'Accepted' by the question author and 'Recommended' by moderators, which helps users know the answer solved the author's problem.