Cross-source coverage
T1096 / ATT&CK
NTFS File Attributes
ATT&CK has retired this technique. Rules still tag it; the current id is T1564.004 Hide Artifacts: NTFS File Attributes.
3 rules · 2 families across 1 source.
1 deprecated hidden · include
From MITRE ATT&CK 19.2
Every New Technology File System (NTFS) formatted partition contains a Master File Table (MFT) that maintains a record for every file/directory on the partition. Within MFT entries are file attributes, such as Extended Attributes (EA) and Data [known as Alternate Data Streams (ADSs) when more than one Data attribute is present], that can be used to store arbitrary data (and even complete files).
Adversaries may store malicious data or binaries in file attribute metadata instead of directly in files. This may be done to evade some defenses, such as static indicator scanning tools and anti-virus.
- Tactics
- Stealth
- Platforms
- Windows
- Telemetry
- —
socfortress/Wazuh-Rules
3 rules · 2 families| Detection | Severity | Format |
|---|---|---|
| Sysmon - Event 1: Process creation · NTFS File Attributes (T1096) 2 variants | High | Wazuh XML |
| Sysmon - Event 1: Process creation · NTFS File Attributes (T1096) 2 variants | Low | Wazuh XML |
| Sysmon - Event 3: Network connection by · NTFS File Attributes (T1096) | Low | Wazuh XML |