Threaticon
Toggle sidebar

You're viewing a limited, public preview. Log in for full access.

Log in User Guide
Log in Get started
Detection Strategies DET0432 — Detection Strategy for NTFS File Attribute Abuse (ADS/EAs)
DET0432

Detection Strategy for NTFS File Attribute Abuse (ADS/EAs)

1 analytic(s) · 1 technique(s) detected

Analytics

1
AN1206 Analytic 1206
Windows

Suspicious use of NTFS file attributes such as Alternate Data Streams (ADS) or Extended Attributes (EA) to hide data. Defender perspective: anomalous file creations or modifications containing colon syntax (file.ext:ads), API calls like ZwSetEaFile/ZwQueryEaFile, or PowerShell/Windows utilities interacting with -stream parameters. Correlation across file metadata anomalies, process lineage, and command execution provides context.

WinEventLog:Sysmon EventCode=11 WinEventLog:Sysmon EventCode=1 WinEventLog:Sysmon EventCode=15 etw:Microsoft-Windows-Kernel-File ZwSetEaFile or ZwQueryEaFile function calls
[ADSPathWhitelist] Exclude legitimate ADS usage by system or AV tools.
[ProcessScope] Restrict monitoring to suspicious parent processes (e.g., powershell.exe, cmd.exe, wscript.exe).
[TimeWindow] Correlate ADS creation with subsequent process execution to strengthen malicious context.

Detected Techniques

1

Details

MITRE ID
DET0432
STIX ID
x-mitre-detection-strategy--08f7fa2b-13f3-4348-83b8-023c2a68493f
Analytics
1
Techniques Detected
1
By Tactic
Stealth
1
Leaving Threaticon

This link opens an external site that isn't part of the platform.