Hidden Executable In NTFS Alternate Data Stream

 Original Source: [Sigma source]
Title: Hidden Executable In NTFS Alternate Data Stream
Status: test
Description:Detects the creation of an ADS (Alternate Data Stream) that contains an executable by looking at a non-empty Imphash
References:
  -https://twitter.com/0xrawsec/status/1002478725605273600?s=21
Author: Florian Roth (Nextron Systems), @0xrawsec
Date: 2018-06-03
modified:2023-02-10
Tags:
  • -'attack.stealth'
  • -'attack.s0139'
  • -'attack.t1564.004'
Logsource:
  • product: windows
  • category: create_stream_hash
  • definition: Requirements: Sysmon or equivalent configured with Imphash logging
Detection:
  selection:
    Hash|contains: 'IMPHASH='
  filter_main_null:
    Hash|contains: 'IMPHASH=00000000000000000000000000000000'
  condition:selection and not 1 of filter_main_*
Falsepositives:
  -This rule isn't looking for any particular binary characteristics. As legitimate installers and programs were seen embedding hidden binaries in their ADS. Some false positives are expected from browser processes and similar.
Level: medium