Potential Hidden Directory Creation Via NTFS INDEX_ALLOCATION Stream

 Original Source: [Sigma source]
Title: Potential Hidden Directory Creation Via NTFS INDEX_ALLOCATION Stream
Status: test
Description:Detects the creation of hidden file/folder with the "::$index_allocation" stream. Which can be used as a technique to prevent access to folder and files from tooling such as "explorer.exe" and "powershell.exe"
References:
  -https://twitter.com/pfiatde/status/1681977680688738305
  -https://soroush.me/blog/2010/12/a-dotty-salty-directory-a-secret-place-in-ntfs-for-secret-files/
  -https://sec-consult.com/blog/detail/pentesters-windows-ntfs-tricks-collection/
  -https://github.com/redcanaryco/atomic-red-team/blob/5c3b23002d2bbede3c07e7307165fc2a235a427d/atomics/T1564.004/T1564.004.md#atomic-test-5---create-hidden-directory-via-index_allocation
  -https://learn.microsoft.com/en-us/openspecs/windows_protocols/ms-fscc/c54dec26-1551-4d3a-a0ea-4fa40f848eb3
Author: Scoubi (@ScoubiMtl)
Date: 2023-10-09
modified:None
Tags:
  • -'attack.stealth'
  • -'attack.t1564.004'
Logsource:
  • product: windows
  • category: file_event
Detection:
  selection:
    TargetFilename|contains: '::$index_allocation'
  condition:selection
Falsepositives:
  -Unlikely
Level: medium