Vulnerabilities Security AI Security Threats
Vendors Microsoft RHEL / Red Hat Java

How Mark of the Web (MotW) Works in Windows 10 and Windows 11?

Mark of the Web (MotW) is Windows’ quiet, persistent way of remembering that a file arrived from the internet (or another untrusted source). It does not scan content or declare a file malicious. Instead, it attaches a small origin tag so the operating system and applications can treat the file more cautiously. This mechanism works the same core way in Windows 10 and Windows 11, with Windows 11 layering additional modern protections on top of it.


What MotW Actually Is

MotW is stored as an NTFS Alternate Data Stream named Zone.Identifier. NTFS files can have a main data stream (the content you normally see) plus zero or more named streams that stay invisible in ordinary File Explorer views and do not change the reported file size.

When a browser, email client, or other supported application saves a file from an untrusted location, it writes (or lets the system write) this stream. A typical example looks like this:


[ZoneTransfer]
ZoneId=3
ReferrerUrl=https://example.com/download-page
HostUrl=https://cdn.example.com/files/setup.exe
  • ZoneId is the key value.
    • 0 = Local machine
    • 1 = Local intranet
    • 2 = Trusted sites
    • 3 = Internet (the most common for web downloads)
    • 4 = Restricted sites

Windows 10 and later commonly include the referrer and host URLs. Earlier implementations often stored only the ZoneId. The exact fields depend on the application that created the mark.

Because the data lives in an NTFS ADS, the mark disappears if the file is copied to a non-NTFS volume (FAT32, exFAT, many USB sticks, network shares that do not preserve streams, or certain archive extractions). This is both a limitation and a common bypass vector.

How the Tag Gets Applied

Most modern browsers (Edge, Chrome, Firefox) and Microsoft apps participate by using Windows APIs such as IAttachmentExecute or by writing the stream directly. Email attachments and files saved from certain cloud services often receive the same treatment. Locally created files normally have no MotW. Files copied from another computer that already carried the mark can retain it if the copy operation preserves ADS.

What Happens When a Marked File Is Opened

The presence of MotW influences several layers:

  • File Explorer and shell — You may see the familiar “This file came from another computer and might be blocked to help protect this computer” message on the General tab of Properties, along with an Unblock checkbox. Checking it and applying removes the Zone.Identifier stream.
  • Executables — Windows Defender SmartScreen evaluates reputation. A MotW-tagged unknown or low-reputation binary commonly triggers a warning. In Windows 11, Smart App Control can go further by assessing code that the program loads.
  • Microsoft Office — Documents open in Protected View by default. Macros are blocked unless the user explicitly enables them (and the mark is often cleared after the user overrides the warning on an executable).
  • Scripts and other content — PowerShell, certain script hosts, and other components can apply stricter policies.
  • Recent Windows 11 refinements — Starting with security updates around October 2025, File Explorer began blocking preview-pane rendering for many MotW files to reduce risks such as NTLM credential leakage. Later optional updates (for example KB5124010) made the behavior more selective—restoring previews for many non-HTML formats while still respecting the underlying security boundary.

MotW itself is not a full security verdict; it is context. SmartScreen reputation, antivirus, and application-specific policies make the actual allow/block decisions.

How to Inspect the Mark Yourself

You do not need third-party tools.

  1. Quick visual check
    Right-click the file → Properties → General tab. If the Security section and Unblock checkbox appear, MotW is present.
  2. View the raw stream
    In Command Prompt or PowerShell (in the folder containing the file):
    notepad filename.ext:Zone.Identifier
    or
    Get-Content .\filename.ext -Stream Zone.Identifier
  3. List streams
    dir /r shows ADS entries. PowerShell’s Get-Item -Stream * is also useful.

Removing the mark is equally straightforward: use the Unblock checkbox, or run Unblock-File .\filename.ext in PowerShell. Once removed, the extra warnings and restrictions tied to that stream no longer apply.

Limitations and Real-World Behavior

  • MotW is NTFS-only. Moving a file off NTFS strips it.
  • Not every download receives a full set of URL fields; some streams contain only ZoneId=3.
  • Container formats (ISO, VHD, certain archives) have historically been used to deliver unmarked inner files. Microsoft has tightened propagation rules over time, especially for its own tools, but third-party extractors may still drop the mark.
  • The mark does not travel with the file when it is emailed, uploaded to many cloud services, or transferred via protocols that ignore ADS.
  • Clearing MotW does not make a file “safe.” It only removes the origin flag that Windows and apps use for extra caution.

Why It Still Matters in 2026

MotW is a lightweight, long-standing foundation rather than a flashy new feature. Windows 10 and Windows 11 both rely on it for consistent origin tracking. Windows 11 simply builds more modern defenses (Smart App Control, tighter preview handling, better container propagation) on top of the same ADS mechanism. Understanding the mark helps explain why a freshly downloaded installer or Office document behaves differently from one you created yourself, and it gives you a precise way to inspect or clear the tag when you have verified a file’s legitimacy.

In short, every time Windows reminds you that a file “came from another computer,” you are seeing MotW at work—an invisible sticky note that has protected users for years by simply remembering where the file came from.

Comments

Post a Comment

←Previous Next→
LIVE CVEs
Loading latest vulnerabilities...