Sysmon EventCode 15 records content of the primary data stream
I recently installed Sysmon version 15.15 on multiple Windows 11 machines using a custom configuration file with no filtering on EventCode 15.
From my understanding, EventCode 15 should be generated whenever an alternate data stream (ADS) of a file is created. However, it appears that this event is also being logged in other scenarios.
After monitoring the generated logs over the past few months, I noticed that, in certain cases, the content of the primary data stream (i.e., the actual file content, not an ADS) is included in the log when specific processes — namely MSSense.exe and chrome.exe — trigger the event. This occurs even though these processes are not expected to perform any file creation actions.
For instance:
When Microsoft Defender scans the file system, it generates numerous EventCode 15 entries containing the primary data stream of the scanned files.
Occasionally, when Chrome downloads a file, it generates two events: one corresponding to the creation of the ADS (related to the Zone.Identifier) and another showing the primary data stream of the file.
I suspect that this behavior may be related to the low-level file-handling functions used by these processes. Nevertheless, I would greatly appreciate your insights or confirmation regarding this observation.