1200KM / simulation
T1564.004 NTFS File Attributes — Attack Simulation
Adversaries may use NTFS file attributes to hide their malicious data in order to evade detection. Every New Technology File System (NTFS) formatted partition contains a Master File Table (MFT) that maintains a record for every file/directory on the partition. Within MFT entries are file attributes, such as Extended Attributes (EA) and Data [known as Alternate Data Streams (ADSs) when more than one Data attribute is present], that can be used to…
Technique description
Adversaries may use NTFS file attributes to hide their malicious data in order to evade detection. Every New Technology File System (NTFS) formatted partition contains a Master File Table (MFT) that maintains a record for every file/directory on the partition. Within MFT entries are file attributes, such as Extended Attributes (EA) and Data [known as Alternate Data Streams (ADSs) when more than one Data attribute is present], that can be used to…
At least one platform-compatible Atomic procedure is documented. Individual review, lab prerequisites, and validation remain required.
Official ATT&CK definition · Detection rules and anomaly models
Documented simulation candidates
- Create ADS PowerShell
Procedure 0045ea16-ed3c-4d4c-a9ee-15e44d1560d1; elevation not declared required; cleanup present, not reviewed. Not executed or individually validated.
- Create ADS command prompt
Procedure 17e7637a-ddaf-4a82-8622-377e20de8fdb; elevation not declared required; cleanup present, not reviewed. Not executed or individually validated.
- Store file in Alternate Data Stream (ADS)
Procedure 2ab75061-f5d5-4c1a-b666-ba2a50df5b02; elevation not declared required; cleanup present, not reviewed. Not executed or individually validated.
- Create Hidden Directory via $index_allocation
Procedure 3e6791e7-232c-481c-a680-a52f86b83fdf; elevation not declared required; cleanup present, not reviewed. Not executed or individually validated.
- Alternate Data Streams (ADS)
Procedure 8822c3b0-d9f9-4daf-a043-49f4602364f4; elevation required; cleanup not declared. Not executed or individually validated.
Connected ecosystem references
Linked tags
Detection and collection
Attack tools
Threat actor context
These are explicit actor-to-technique associations in the existing Threat Matrix snapshot, not attribution of an event or proof that a detector identifies the actor. No tool-to-actor relationship is inferred.
Existing research
Pinned research references. No browser attack runner, live simulation result or validated detector is asserted. Source mappings and validation limits are preserved. ATT&CK / Atomic provenance · Detection provenance.