Sub-technique of T1564 Hide Artifacts.View on attack.mitre.org
Adversaries may use NTFS file attributes to hide their malicious data in order to evade detection. Every New Technology File System (NTFS) formatted partition contains a Master File Table (MFT) that maintains a record for every file/directory on the partition. Within MFT entries are file attributes, such as Extended Attributes (EA) and Data [known as Alternate Data Streams (ADSs) when more than one Data attribute is present], that can be used to store arbitrary data (and even complete files).
Adversaries may store malicious data or binaries in file attribute metadata instead of directly in files. This may be done to evade some defenses, such as static indicator scanning tools and anti-virus.
Rules on DetectionCode tagged with T1564.004.
| Rule | Type | Risk | Data source |
|---|---|---|---|
| Windows Alternate Data Stream Created Over Local Share | Anomaly | NULL | Windows Event Log Security 5145 |
| Windows Alternate DataStream - Base64 Content | TTP | NULL | Sysmon EventID 15 |
| Windows Alternate DataStream - Executable Content | TTP | NULL | Sysmon EventID 15 |
| Windows Alternate DataStream - Process Execution | TTP | NULL | Windows Event Log Security 4688, Sysmon EventID 1 |
| Windows SymbolicLink-Testing-Tools Utility Execution | TTP | NULL | Sysmon EventID 1, Windows Event Log Security 4688, CrowdStrike ProcessRollup2 |
| Windows Wermgr Alternate Data Stream in Temp Dir | Anomaly | NULL | Sysmon EventID 15 |
None recorded.
| Used by | Procedure example |
|---|---|
| MalwareAnchor | Anchor has used NTFS to hide files. |
| MalwareAstaroth | Astaroth can abuse alternate data streams (ADS) to store content for malicious payloads. |
| MalwareBitPaymer | BitPaymer has copied itself to the |
| MalwareDEADEYE | The DEADEYE.EMBED variant of DEADEYE can embed its payload in an alternate data stream of a local file. |
| Toolesentutl | esentutl can be used to read and write alternate data streams. |
| ToolExpand | Expand can be used to download or copy a file into an alternate data stream. |
| MalwareGazer | Gazer stores configuration items in alternate data streams (ADSs) if the Registry is not accessible. |
| MalwareLatrodectus | Latrodectus can delete itself while its process is still running through the use of an alternate data stream. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.