BIOC Informational

Scripting engine creates an Alternate Data Stream (ADS)

Malware may hide data inside alternate data streams instead of inside a file.

Module:
Platform Analytics
Agent event type:
File
Category:
Evasion
Status:
Enabled
ATT&CK tactics: Defense Evasion (TA0005)
ATT&CK techniques: Hide Artifacts: NTFS File Attributes (T1564.004)
Indicator:

File action type = create , delete AND file name = *:* Process initiated by = wscript.exe , cscript.exe , cmd.exe , powershell.exe , mshta.exe , psw.exe , python.exe , java.exe , javaw.exe , regsvr32.exe , expand.exe , lua.exe , ruby.exe , cgo name = wscript.exe , cscript.exe , cmd.exe , powershell.exe , mshta.exe , psw.exe , python.exe , java.exe , javaw.exe , regsvr32.exe , expand.exe , lua.exe , ruby.exe

Preventable: yes