## What is Sysmon? * [Sysmon](https://learn.microsoft.com/en-us/sysinternals/downloads/sysmon) is a powerful tool to monitoring system event sources * Installs a Protected Kernel Driver * Accesses many sources of telemetry * Includes an XML based rule language to allow selectively reporting and filtering events. --- ## Evidence of Download * Mark of the Web - An ADS added to downloaded files to indicate where they were downloaded from.
--- ## Evidence of Download
--- ## Evidence of Download: Sysmon * Sysmon can record ADS creation with Event ID 15
--- ## Evidence of Download: Sysmon
--- ## Where did this Executable come from? * Since Sysmon 15 we have a new event type for written Executables. ```xml
C:\ProgramData\
C:\Users\
``` --- ## Where did this Executable come from?