Execute From Alternate Data Streams

 Original Source: [Sigma source]
Title: Execute From Alternate Data Streams
Status: test
Description:Detects execution from an Alternate Data Stream (ADS). Adversaries may use NTFS file attributes to hide their malicious data in order to evade detection
References:
  -https://github.com/redcanaryco/atomic-red-team/blob/f339e7da7d05f6057fdfcdd3742bfcf365fee2a9/atomics/T1564.004/T1564.004.md
Author: frack113
Date: 2021-09-01
modified:2022-10-09
Tags:
  • -'attack.stealth'
  • -'attack.t1564.004'
Logsource:
  • category: process_creation
  • product: windows
Detection:
  selection_stream:
    CommandLine|contains: 'txt:'
  selection_tools_type:
    CommandLine|contains|all:
      -'type '
      -' > '

  selection_tools_makecab:
    CommandLine|contains|all:
      -'makecab '
      -'.cab'

  selection_tools_reg:
    CommandLine|contains|all:
      -'reg '
      -' export '

  selection_tools_regedit:
    CommandLine|contains|all:
      -'regedit '
      -' /E '

  selection_tools_esentutl:
    CommandLine|contains|all:
      -'esentutl '
      -' /y '
      -' /d '
      -' /o '

  condition:selection_stream and (1 of selection_tools_*)
Falsepositives:
  -Unknown
Level: medium