ATT&CK · T1564.004 · sub-technique
NTFS File Attributes
Tactics: stealth
About
Adversaries may use NTFS file attributes to hide their malicious data in order to evade detection. Every New Technology File System (NTFS) formatted partition contains a Master File Table (MFT) that maintains a record for every file/directory on the partition. Within MFT entries are file attributes, such as Extended Attributes (EA) and Data [known as Alternate Data Streams (ADSs) when more than one Data attribute is present], that can be used to store arbitrary data (and even complete files). Adversaries may store malicious data or binaries in file attribute metadata instead of directly in files. This may be done to evade some defenses, such as static indicator scanning tools and anti-virus.
Used by actors
1 known groups
Software
15 malware/tools implement this
Corpus indicators tagged with this technique
217 indicators in the corpus carry T1564.004.
Showing the top 30 by severity of 217.