kevmap

TechniquesT1564 › T1564.004

T1564.004 NTFS File Attributes

stealth — Windows · attack.mitre.org · JSON

1
MITRE detection strategy
1
analytics
23
Sigma rules tagged attack.t1564.004
0
KEV CVEs mapped here
<p>Adversaries may use NTFS file attributes to hide their malicious data in order to evade detection. Every New Technology File System (NTFS) formatted partition contains a Master File Table (MFT) that maintains a record for every file/directory on the partition. Within MFT entries are file attributes, such as Extended Attributes (EA) and Data [known as Alternate Data Streams (ADSs) when more than one Data attribute is present], that can be used to store arbitrary data (and even complete files).</p><p>Adversaries may store malicious data or binaries in file attribute metadata instead of directly in files. This may be done to evade some defenses, such as static indicator scanning tools and anti-virus.</p>

KEV CVEs mapped to this technique · CTID Mappings Explorer

None. No KEV entry in the public mapping names this technique. Given that 74.7% of KEV has no mapping at all, this says more about the mapping than about the technique.

Detection strategy · ATT&CK Enterprise v19.2

Sigma rules · SigmaHQ da9bb07d64, tag attack.t1564.004

Author: Nasreddine Bencherchali (Nextron Systems), Florian Roth (Nextron Systems) · 2022-09-07 (modified 2023-02-10) · logsource: product=windows category=create_stream_hash · 025bd229-fd1f-4fdb-97ab-20006e1a5368
Detects the download of suspicious file type from URLs with IP
Techniques: T1564.004
Author: Furkan CALISKAN, @caliskanfurkan_, @oscd_initiative, Nasreddine Bencherchali (Nextron Systems) · 2020-10-05 (modified 2024-03-05) · logsource: product=windows category=process_creation · 04936b66-3915-43ad-a8e5-809eadfd1141
Detects execution of findstr with the "s" and "i" flags for a "subfolder" and "insensitive" search respectively. Attackers sometimes leverage this built-in utility to search the system for interesting files or filter through results of commands.
Author: Nasreddine Bencherchali (Nextron Systems), Scoubi (@ScoubiMtl) · 2023-10-09 · logsource: product=windows category=process_creation · 0900463c-b33b-49a8-be1d-552a3b553dae
Detects command line containing reference to the "::$index_allocation" stream, which can be used as a technique to prevent access to folders or files from tooling such as "explorer.exe" or "powershell.exe"
Techniques: T1564.004
Author: Oddvar Moe, Sander Wiebing, oscd.community · 2020-10-07 (modified 2021-11-27) · logsource: product=windows category=create_stream_hash · 0d7a9363-af70-4e7b-a3b7-1a176b7fbe84
Exports the target Registry key and hides it in the specified alternate data stream.
Techniques: T1564.004
Author: Florian Roth (Nextron Systems) · 2022-08-24 (modified 2024-11-23) · logsource: product=windows category=create_stream_hash · 19b041f6-e583-40dc-b842-d6fa8011493f
Detects the creation of a named file stream with the imphash of a well-known hack tool
Techniques: T1564.004
Author: frack113, Nasreddine Bencherchali · 2022-08-07 (modified 2025-10-22) · logsource: product=windows category=process_creation · 349d891d-fef0-4fe4-bc53-eee623a15969
Detects the use of short name paths (8.3 format) in command lines, which can be used to obfuscate paths or access restricted locations. Windows creates short 8.3 filenames (like PROGRA~1) for compatibility with MS-DOS-based or 16-bit Windows programs. When investigating, examine: - Commands using short paths to access sensitive directories or files - Web servers on Windows (especially Apache) where short filenames could bypass security controls - Correlation with other suspicious behaviors - baseline of short name usage in your environment and look for deviations
Techniques: T1564.004
Author: Omar Khaled (@beacon_exe) · 2024-08-21 · logsource: product=macos category=process_creation · 3b2c1059-ae5f-40b6-b5d4-6106d3ac20fe
Detects the execution of the "chflags" utility with the "hidden" flag, in order to hide files on MacOS. When a file or directory has this hidden flag set, it becomes invisible to the default file listing commands and in graphical file browsers.
Author: frack113, Nasreddine Bencherchali (Nextron Systems) · 2022-08-06 (modified 2023-07-20) · logsource: product=windows category=process_creation · 3ef5605c-9eb9-47b0-9a71-b727e6aa5c3b
Detect use of the Windows 8.3 short name. Which could be used as a method to avoid Image based detection
Techniques: T1564.004
Author: Sergey Soldatov, Kaspersky Lab, oscd.community · 2019-10-30 (modified 2022-07-14) · logsource: product=windows category=process_creation · 45a594aa-1fbd-4972-a809-ff5a99dd81b8
Detects PowerShell script execution from Alternate Data Stream (ADS)
Techniques: T1564.004
Author: frack113 · 2021-11-26 (modified 2022-12-30) · logsource: product=windows category=process_creation · 4b13db67-0c45-40f1-aba8-66a1a7198a1e
Extract data from cab file and hide it in an alternate data stream
Techniques: T1564.004
Author: Florian Roth (Nextron Systems) · 2022-08-24 (modified 2026-03-29) · logsource: product=windows category=create_stream_hash · 52182dfb-afb7-41db-b4bc-5336cb29b464
Detects the download of suspicious file type from a well-known file and paste sharing domain
Techniques: T1564.004
Author: Furkan CALISKAN, @caliskanfurkan_, @oscd_initiative, Nasreddine Bencherchali (Nextron Systems) · 2020-10-05 (modified 2024-03-05) · logsource: product=windows category=process_creation · 587254ee-a24b-4335-b3cd-065c0f1f4baa
Detects execution of "findstr" with specific flags and a remote share path. This specific set of CLI flags would allow "findstr" to download the content of the file located on the remote share as described in the LOLBAS entry.
Author: frack113 · 2021-11-26 (modified 2022-12-31) · logsource: product=windows category=process_creation · 6b369ced-4b1d-48f1-b427-fdc0de0790bd
Compress target file into a cab file stored in the Alternate Data Stream (ADS) of the target file.
Techniques: T1564.004
Author: frack113 · 2021-09-01 (modified 2022-10-09) · logsource: product=windows category=process_creation · 7f43c430-5001-4f8b-aaa9-c3b88f18fa5c
Detects execution from an Alternate Data Stream (ADS). Adversaries may use NTFS file attributes to hide their malicious data in order to evade detection
Techniques: T1564.004
Author: Sami Ruohonen · 2018-07-24 (modified 2022-12-25) · logsource: product=windows category=ps_script · 8c521530-5169-495d-a199-0a3a881ad24e
Detects writing data into NTFS alternate data streams from powershell. Needs Script Block Logging.
Techniques: T1564.004T1059.001
Author: Harjot Singh, '@cyb3rjy0t' · 2023-01-21 (modified 2026-03-16) · logsource: product=windows category=process_creation · 9248c7e1-2bf3-4661-a22c-600a8040b446
Detects execution of rundll32 where the DLL being called is stored in an Alternate Data Stream (ADS).
Techniques: T1564.004
Author: frack113 · 2021-09-02 (modified 2022-12-25) · logsource: product=windows category=ps_script · a699b30e-d010-46c8-bbd1-ee2e26765fe9
Storing files in Alternate Data Stream (ADS) similar to Astaroth malware.
Techniques: T1564.004
Author: Scoubi (@ScoubiMtl) · 2023-10-09 · logsource: product=windows category=file_event · a8f866e1-bdd4-425e-a27a-37619238d9c7
Detects the creation of hidden file/folder with the "::$index_allocation" stream. Which can be used as a technique to prevent access to folder and files from tooling such as "explorer.exe" and "powershell.exe"
Techniques: T1564.004
Author: frack113, Nasreddine Bencherchali · 2022-08-07 (modified 2025-10-20) · logsource: product=windows category=process_creation · a96970af-f126-420d-90e1-d37bf25e50e1
Detect use of the Windows 8.3 short name. Which could be used as a method to avoid Image detection
Techniques: T1564.004
Author: Florian Roth (Nextron Systems) · 2022-08-24 (modified 2026-03-29) · logsource: product=windows category=create_stream_hash · ae02ed70-11aa-4a22-b397-c0d0e8f6ea99
Detects the download of suspicious file type from a well-known file and paste sharing domain
Techniques: T1564.004
Author: Florian Roth (Nextron Systems), @0xrawsec · 2018-06-03 (modified 2023-02-10) · logsource: product=windows category=create_stream_hash · b69888d4-380c-45ce-9cf9-d9ce46e67821
Detects the creation of an ADS (Alternate Data Stream) that contains an executable by looking at a non-empty Imphash
Techniques: T1564.004
Author: frack113 · 2022-05-02 · logsource: product=windows category=process_creation · cafeeba3-01da-4ab4-b6c4-a31b1d9730c7
Detects the execution of the LOLBIN PrintBrm.exe, which can be used to create or extract ZIP files. PrintBrm.exe should not be run on a normal workstation.
Techniques: T1105T1564.004
Author: frack113, Nasreddine Bencherchali (Nextron Systems) · 2022-08-05 (modified 2022-09-21) · logsource: product=windows category=process_creation · dd6b39d9-d9be-4a3b-8fe0-fe3c6a5c1795
Detect use of the Windows 8.3 short name. Which could be used as a method to avoid command-line detection
Techniques: T1564.004

Rules tagged at the parent level (attack.t1564) 10

These target the parent technique, not this sub-technique specifically. Listed for completeness, not counted as coverage.

Author: frack113 · 2021-06-04 (modified 2022-08-02) · logsource: product=windows category=sysmon_status · 1f2b5353-573f-4880-8e33-7d04dcf97744
Detects when an attacker tries to hide from Sysmon by disabling or stopping it
Techniques: T1564
Author: Tobias Michalski (Nextron Systems) · 2022-02-24 (modified 2023-08-17) · logsource: product=windows category=registry_set · 2ff692c2-4594-41ec-8fcb-46587de769e0
Detects disabling the CrashDump per registry (as used by HermeticWiper)
Techniques: T1564T1112
Author: Florian Roth (Nextron Systems) · 2023-05-08 (modified 2024-11-23) · logsource: product=windows category=process_creation · 5722dff1-4bdd-4949-86ab-fbaf707e767a
Detects the execution of System Informer, a task manager tool to view and manipulate processes, kernel options and other low level operations
Techniques: T1082T1564T1543
Author: Florian Roth (Nextron Systems), Nasreddine Bencherchali (Nextron Systems) · 2022-02-25 (modified 2024-07-12) · logsource: product=windows category=process_creation · 69bd9b97-2be2-41b6-9816-fb08757a4d1a
Detects a potentially suspicious execution of a parent process located in the "\Users\Public" folder executing a child process containing references to shell or scripting binaries and commandlines.
Techniques: T1564T1059
Author: frack113 · 2022-09-05 (modified 2023-12-11) · logsource: product=windows category=file_event · 74babdd6-a758-4549-9632-26535279e654
Detect creation of suspicious executable file names. Some strings look for suspicious file extensions, others look for filenames that exploit unquoted service paths.
Techniques: T1564
Author: Florian Roth (Nextron Systems) · 2022-10-10 (modified 2024-11-23) · logsource: product=windows category=process_creation · 811e0002-b13b-4a15-9d00-a613fce66e42
Detects the execution of Process Hacker based on binary metadata information (Image, Hash, Imphash, etc). Process Hacker is a tool to view and manipulate processes, kernel options and other low level options. Threat actors abused older vulnerable versions to manipulate system processes.
Techniques: T1622T1564T1543
Author: frack113 · 2021-06-04 (modified 2026-07-23) · logsource: product=windows category=sysmon_error · 815cd91b-7dbc-4247-841a-d7dd1392b0a8
Detects when an adversary is trying to hide it's action from Sysmon logging based on error messages
Techniques: T1564
Author: Janantha Marasinghe · 2020-09-26 (modified 2025-07-29) · logsource: product=windows category=process_creation · bab049ca-7471-4828-9024-38279a4c04da
Adversaries can carry out malicious operations using a virtual instance to avoid detection. This rule is built to detect the registration of the Virtualbox driver or start of a Virtualbox VM.
Techniques: T1564.006T1564
Author: frack113 · 2022-01-21 (modified 2023-01-05) · logsource: product=windows category=file_event · e15b518d-b4ce-4410-a9cd-501f23ce4a18
Once executed, colorcpl.exe will copy the arbitrary file to c:\windows\system32\spool\drivers\color\
Techniques: T1564
Author: Joseliyo Sanchez, @Joseliyo_Jstnk · 2023-01-12 · logsource: product=linux category=process_creation · ec52985a-d024-41e3-8ff6-14169039a0b3
Detects execution of the "mount" command with "hidepid" parameter to make invisible processes to other users from the system
Techniques: T1564