Skip to content
Threat Feed
medium advisory

Detection of NTFS Alternate Data Stream Manipulation via PowerShell

Adversaries utilize NTFS Alternate Data Streams (ADS) to conceal malicious payloads and configuration data on Windows systems by appending information to existing files.

NTFS Alternate Data Streams (ADS) are a feature of the Windows New Technology File System (NTFS) that allows data to be attached to a file without changing its size or visibility in standard directory listings. Attackers leverage this capability to hide malware, configuration files, or staging tools from traditional file-based detection mechanisms and manual inspection. By using PowerShell cmdlets such as Set-Content or Add-Content with the -Stream parameter, actors can write arbitrary content into these streams. While ADS has legitimate use cases in Windows, such as storing file metadata or zone identifiers, its abuse for concealment is a common technique for persistence, execution, and data staging. Defenders should monitor PowerShell script block logs for patterns indicating the use of these cmdlets in conjunction with stream targeting.

Impact

Successful abuse of ADS allows attackers to maintain stealthy persistence and stage malicious payloads on compromised systems. This technique hinders forensic analysis and evades standard file integrity monitoring tools, potentially leading to unauthorized code execution, credential harvesting, or exfiltration of sensitive data that is hidden within legitimate host files.

Recommendation

Prioritize visibility into PowerShell execution by ensuring Script Block Logging (Event ID 4104) is enabled and forwarded to the SIEM.

  • Deploy the provided Sigma rule to detect PowerShell-based ADS manipulation.
  • Monitor for unauthorized modification of critical system files where ADS may be used to inject malicious code.
  • Investigate alerts triggered by non-standard processes using the -Stream parameter, particularly when associated with common system utilities or user-writable directories.

Immediate actions

Enable PowerShell Script Block Logging (Event ID 4104) across all endpoints

IT Operations 48h

Threat Hunt

Search for logs containing '-Stream' in PowerShell script blocks

T1564.004 medium medium confidence convert to detection

Data: Event ID 4104

Detection coverage 1

Detect PowerShell NTFS Alternate Data Stream Access

medium

Detects the creation or modification of NTFS alternate data streams using PowerShell cmdlets Set-Content or Add-Content.

sigma tactics: stealth techniques: T1564.004 sources: ps_script, windows

Detection queries are available on the platform. Get full rules →