BIOC
Informational
✕
Scripting engine creates an Alternate Data Stream (ADS)
Malware may hide data inside alternate data streams instead of inside a file.
- Module:
- Platform Analytics
- Agent event type:
- File
- Category:
- Evasion
- Status:
- Enabled
ATT&CK tactics: Defense Evasion (TA0005)
ATT&CK techniques: Hide Artifacts: NTFS File Attributes (T1564.004)
Indicator:
File action type = create , delete AND file name = *:* Process initiated by = wscript.exe , cscript.exe , cmd.exe , powershell.exe , mshta.exe , psw.exe , python.exe , java.exe , javaw.exe , regsvr32.exe , expand.exe , lua.exe , ruby.exe , cgo name = wscript.exe , cscript.exe , cmd.exe , powershell.exe , mshta.exe , psw.exe , python.exe , java.exe , javaw.exe , regsvr32.exe , expand.exe , lua.exe , ruby.exe
Preventable: yes