1200KM / detection
T1564.004 NTFS File Attributes — Detection Rules
Detection workspace for T1564.004 NTFS File Attributes: 22 Sigma sources, 0 Atlas concepts and 0 anomaly models. No live detection validation.
Source-backed rule directory
- Hidden Flag Set On File/Directory Via Chflags - MacOS · test · medium · {"product":"macos","category":"process_creation"}
- Hidden Executable In NTFS Alternate Data Stream · test · medium · {"product":"windows","category":"create_stream_hash","definition":"Requirements: Sysmon or equivalent configured with Imphash logging"}
- Suspicious File Download From File Sharing Websites - File Stream · test · high · {"product":"windows","category":"create_stream_hash"}
- Unusual File Download From File Sharing Websites - File Stream · test · medium · {"product":"windows","category":"create_stream_hash"}
- HackTool Named File Stream Created · test · high · {"product":"windows","category":"create_stream_hash","definition":"Requirements: Sysmon config with Imphash logging activated"}
- Exports Registry Key To an Alternate Data Stream · test · high · {"product":"windows","category":"create_stream_hash"}
- Unusual File Download from Direct IP Address · test · high · {"product":"windows","category":"create_stream_hash"}
- Potential Hidden Directory Creation Via NTFS INDEX_ALLOCATION Stream · test · medium · {"product":"windows","category":"file_event"}
- NTFS Alternate Data Stream · test · high · {"product":"windows","category":"ps_script","definition":"Requirements: Script Block Logging must be enabled"}
- Powershell Store File In Alternate Data Stream · test · medium · {"product":"windows","category":"ps_script","definition":"Requirements: Script Block Logging must be enabled"}
- Remote File Download Via Findstr.EXE · test · medium · {"category":"process_creation","product":"windows"}
- Insensitive Subfolder Search Via Findstr.EXE · test · low · {"category":"process_creation","product":"windows"}
- Suspicious Diantz Alternate Data Stream Execution · test · medium · {"category":"process_creation","product":"windows"}
- Suspicious Extrac32 Alternate Data Stream Execution · test · medium · {"category":"process_creation","product":"windows"}
- PrintBrm ZIP Creation of Extraction · test · high · {"product":"windows","category":"process_creation"}
- Run PowerShell Script from ADS · test · high · {"category":"process_creation","product":"windows"}
- Potential Rundll32 Execution With DLL Stored In ADS · test · high · {"category":"process_creation","product":"windows"}
- Execute From Alternate Data Streams · test · medium · {"category":"process_creation","product":"windows"}
- Potential Hidden Directory Creation Via NTFS INDEX_ALLOCATION Stream - CLI · test · medium · {"product":"windows","category":"process_creation"}
- Use Short Name Path in Image · test · medium · {"category":"process_creation","product":"windows"}
- Use NTFS Short Name in Command Line · test · medium · {"category":"process_creation","product":"windows"}
- Use NTFS Short Name in Image · test · medium · {"category":"process_creation","product":"windows"}
Atlas deterministic concepts
No exact concept selected.
Anomaly models
No exact Atlas model in this snapshot.
ATT&CK analytic guidance
DET0432 Detection Strategy for NTFS File Attribute Abuse (ADS/EAs)
AN1206 Analytic 1206
Suspicious use of NTFS file attributes such as Alternate Data Streams (ADS) or Extended Attributes (EA) to hide data. Defender perspective: anomalous file creations or modifications containing colon syntax (file.ext:ads), API calls like ZwSetEaFile/ZwQueryEaFile, or PowerShell/Windows utilities interacting with -stream parameters. Correlation across file metadata anomalies, process lineage, and command execution provides context.
Connected ecosystem references
Linked tags
Simulation, tools and telemetry
Threat actor context
These are explicit actor-to-technique associations in the existing Threat Matrix snapshot, not attribution of an event or proof that a detector identifies the actor. No tool-to-actor relationship is inferred.
Existing anomaly research
Pinned research references. No browser attack runner, live simulation result or validated detector is asserted. Source mappings and validation limits are preserved. ATT&CK / Atomic provenance · Detection provenance.