Cross-source coverage

T1096 / ATT&CK

NTFS File Attributes

ATT&CK has retired this technique. Rules still tag it; the current id is T1564.004 Hide Artifacts: NTFS File Attributes.

4 rules · 3 families across 2 sources.

Showing deprecated rules · back to the default

From MITRE ATT&CK 19.2

Every New Technology File System (NTFS) formatted partition contains a Master File Table (MFT) that maintains a record for every file/directory on the partition. Within MFT entries are file attributes, such as Extended Attributes (EA) and Data [known as Alternate Data Streams (ADSs) when more than one Data attribute is present], that can be used to store arbitrary data (and even complete files).

Adversaries may store malicious data or binaries in file attribute metadata instead of directly in files. This may be done to evade some defenses, such as static indicator scanning tools and anti-virus.

Tactics
Stealth
Platforms
Windows
Telemetry

socfortress/Wazuh-Rules

3 rules · 2 families
Detection Severity Format
Sysmon - Event 1: Process creation · NTFS File Attributes (T1096) 2 variants High Wazuh XML
Sysmon - Event 1: Process creation · NTFS File Attributes (T1096) 2 variants Low Wazuh XML
Sysmon - Event 3: Network connection by · NTFS File Attributes (T1096) Low Wazuh XML

chronicle/detection-rules

1 rule
Detection Severity Format
possible_abusing_ads Undefined YARA-L

Detection rules belong to the projects that publish them and remain under their own licenses. This site indexes and links to them; it claims no rights in them.