Execute From Alternate Data Streams
Description
Detects execution from an Alternate Data Stream (ADS). Adversaries may use NTFS file attributes to hide their malicious data in order to evade detection
Query · sigma
selection_stream: CommandLine|contains: 'txt:' selection_tools_type: CommandLine|contains|all: - 'type ' - ' > ' selection_tools_makecab: CommandLine|contains|all: - 'makecab ' - .cab selection_tools_reg: CommandLine|contains|all: - 'reg ' - ' export ' selection_tools_regedit: CommandLine|contains|all: - 'regedit ' - ' /E ' selection_tools_esentutl: CommandLine|contains|all: - 'esentutl ' - ' /y ' - ' /d ' - ' /o ' condition: selection_stream and (1 of selection_tools_*)
Known false positives
- Unknown