Heidemann61-9016 avatar image
0 Votes"
Heidemann61-9016 asked Heidemann61-9016 commented

Sysmon not logging Event ID 15 on mapped drives as expected

Having sysmon installed on a client computer (in my case the most recent Windows 10), and having defined event rules for Event ID 15 (FileCreateStreamHash) on the client computer, I found that any download triggers an Event 15 if the download folder is "local" (on a locally attached drive), for example somehow on %systemdrive%, which is what I expected. So, sysmon works.

However, if the download folder resides on a network mapped drive, no Event 15 is logged, at least not on the client computer. For example, if you map Z: on the client computer to \\some-fileserver\some-share, then no download will trigger any Event 15 on the client computer if the download is stored in Z:\download.

On the other hand, a sysmon installed on the file server WILL trigger event 15 in that case, but unfortunately is missing valuable information. For example the process id in that event 15 is not the pid of the browser instance on the client, but the file server service instance, the "image" does not identify the browser, it is SYSTEM.

Q: I assume this behaviour is "works as designed"?

· 1
5 |1600 characters needed characters left characters exceeded

Up to 10 attachments (including images) can be used with a maximum of 3.0 MiB each and 30.0 MiB total.

Because I got no comment nor answer, I think it is "works as designed" that there is no Event ID 15 if the downloaded file is placed on a network drive.

Unfortunately, if the file server is a filer not running with a Microsoft OS (for example netapp) there is no chance to leverage sysmon FileCreateStreamHash. This is what my customer faces in his terminal server / Citrix environments: All user profiles point at least partially to network drives on a netapp filer, especially the download folder does. Thus no sysmon Event 15 when downloading a file.

Is there a way to file a feature request to extend the sysmon capabilities for Event ID 15 with this in mind? I mean, firing an Event ID 15 in sysmon regardless where the file is placed. At the end of the day, it is the client application (browser) which creates a file on a NTFS based file system (on the file server), and the file does carry the MOTW alternate data stream.

Thanks for any suggestions / comments /...

0 Votes 0 ·

0 Answers