Tag
medium
advisory
Abuse of NTFS INDEX_ALLOCATION Stream for Directory Obfuscation
1 rule 1 TTPAttackers can abuse the NTFS $INDEX_ALLOCATION stream to create directories that are inaccessible to standard Windows utilities like Explorer and PowerShell, facilitating stealthy data storage.
stealth
persistence
windows
ntfs
1r
1t
medium
advisory
Execution via NTFS Alternate Data Streams
1 rule 1 TTPAdversaries utilize NTFS Alternate Data Streams to hide and execute malicious payloads, evading detection by conventional file analysis tools.
stealth
persistence
ads
ntfs
windows
1r
1t
medium
advisory
Detection of PowerShell Alternate Data Stream File Storage
1 rule 1 TTPAdversaries utilize PowerShell to store malicious payloads within NTFS Alternate Data Streams (ADS) to evade detection and maintain stealthy persistence.
persistence
stealth
powershell
ntfs
1r
1t