NTFS File Attributes
Adversaries may use NTFS file attributes to hide their malicious data in order to evade detection. Every New Technology File System (NTFS) formatted partition contains a Master File Table (MFT) that maintains a record for every file/directory on the partition. (Citation: SpectorOps Host-Based Jul 2017) Within MFT entries are file attributes, (Citation: Microsoft NTFS File Attributes Aug 2010) such as Extended Attributes (EA) and Data [known as Alternate Data Streams (ADSs) when more than one Dat...
BY SOURCE
PROCEDURES (16)
Auto-extracted: 11 detections for process creation monitoring
Auto-extracted: 3 detections for general monitoring
Auto-extracted: 2 detections for powershell
Auto-extracted: 2 detections for script execution monitoring
Auto-extracted: 2 detections for suspicious
Auto-extracted: 1 detections for remote
Auto-extracted: 1 detections for powershell
Auto-extracted: 1 detections for powershell
Auto-extracted: 1 detections for registry monitoring
Auto-extracted: 1 detections for persist
Auto-extracted: 1 detections for remote
Auto-extracted: 1 detections for persist
Auto-extracted: 1 detections for suspicious
Auto-extracted: 1 detections for suspicious
Auto-extracted: 1 detections for http
Auto-extracted: 1 detections for http