NTFS File Attributes

T1564.004

Sub-technique of T1564 Hide Artifacts.View on attack.mitre.org

About this technique

Adversaries may use NTFS file attributes to hide their malicious data in order to evade detection. Every New Technology File System (NTFS) formatted partition contains a Master File Table (MFT) that maintains a record for every file/directory on the partition. Within MFT entries are file attributes, such as Extended Attributes (EA) and Data [known as Alternate Data Streams (ADSs) when more than one Data attribute is present], that can be used to store arbitrary data (and even complete files).

Adversaries may store malicious data or binaries in file attribute metadata instead of directly in files. This may be done to evade some defenses, such as static indicator scanning tools and anti-virus.

Detection rules29

Rules on DetectionCode tagged with T1564.004.

Sigma23

RuleLevelLog source
Exports Registry Key To an Alternate Data Streamhighwindows / create_stream_hash
HackTool Named File Stream Createdhighwindows / create_stream_hash
NTFS Alternate Data Streamhighwindows / ps_script
Potential Rundll32 Execution With DLL Stored In ADShighwindows / process_creation
PrintBrm ZIP Creation of Extractionhighwindows / process_creation
Run PowerShell Script from ADShighwindows / process_creation
Suspicious File Download From File Sharing Websites - File Streamhighwindows / create_stream_hash
Unusual File Download from Direct IP Addresshighwindows / create_stream_hash
Execute From Alternate Data Streamsmediumwindows / process_creation
Hidden Executable In NTFS Alternate Data Streammediumwindows / create_stream_hash
Hidden Flag Set On File/Directory Via Chflags - MacOSmediummacos / process_creation
Potential Hidden Directory Creation Via NTFS INDEX_ALLOCATION Streammediumwindows / file_event
Potential Hidden Directory Creation Via NTFS INDEX_ALLOCATION Stream - CLImediumwindows / process_creation
Powershell Store File In Alternate Data Streammediumwindows / ps_script
Remote File Download Via Findstr.EXEmediumwindows / process_creation

Splunk6

RuleTypeRiskData source
Windows Alternate Data Stream Created Over Local ShareAnomalyNULLWindows Event Log Security 5145
Windows Alternate DataStream - Base64 ContentTTPNULLSysmon EventID 15
Windows Alternate DataStream - Executable ContentTTPNULLSysmon EventID 15
Windows Alternate DataStream - Process ExecutionTTPNULLWindows Event Log Security 4688, Sysmon EventID 1
Windows SymbolicLink-Testing-Tools Utility ExecutionTTPNULLSysmon EventID 1, Windows Event Log Security 4688, CrowdStrike ProcessRollup2
Windows Wermgr Alternate Data Stream in Temp DirAnomalyNULLSysmon EventID 15

Groups1

Software15

Campaigns0

None recorded.

Procedure examples16

Groups1

Used byProcedure example
GroupAPT32

APT32 used NTFS alternate data streams to hide their payloads.

Software15

Used byProcedure example
MalwareAnchor

Anchor has used NTFS to hide files.

MalwareAstaroth

Astaroth can abuse alternate data streams (ADS) to store content for malicious payloads.

MalwareBitPaymer

BitPaymer has copied itself to the :bin alternate data stream of a newly created file.

MalwareDEADEYE

The DEADEYE.EMBED variant of DEADEYE can embed its payload in an alternate data stream of a local file.

Toolesentutl

esentutl can be used to read and write alternate data streams.

ToolExpand

Expand can be used to download or copy a file into an alternate data stream.

MalwareGazer

Gazer stores configuration items in alternate data streams (ADSs) if the Registry is not accessible.

MalwareLatrodectus

Latrodectus can delete itself while its process is still running through the use of an alternate data stream.

View all 15 software examples

References6

  1. Journey into IR ZeroAccess NTFS EA Open source
    Harrell, C. (2012, December 11). Extracting ZeroAccess from NTFS Extended Attributes. Retrieved June 3, 2016.
  2. MalwareBytes ADS July 2015 Open source
    Arntz, P. (2015, July 22). Introduction to Alternate Data Streams. Retrieved March 21, 2018.
  3. Microsoft ADS Mar 2014 Open source
    Marlin, J. (2013, March 24). Alternate Data Streams in NTFS. Retrieved March 21, 2018.
  4. Microsoft File Streams Open source
    Microsoft. (n.d.). File Streams. Retrieved September 12, 2024.
  5. Microsoft NTFS File Attributes Aug 2010 Open source
    Hughes, J. (2010, August 25). NTFS File Attributes. Retrieved March 21, 2018.
  6. SpectorOps Host-Based Jul 2017 Open source
    Atkinson, J. (2017, July 18). Host-based Threat Modeling & Indicator Design. Retrieved March 21, 2018.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.