BIOC Informational

The scripting engine executed code from an Alternate Data Stream (ADS)

Alternate Data Streams (ADSs) are NTFS Master File Table (MFT) data entries that relate to a file, but are separate from its contents. An attacker may try to evade detection by executing malware from the ADS value of a file.

Module:
Platform Analytics
Agent event type:
Process execution
Category:
Evasion
Status:
Enabled
ATT&CK tactics: Defense Evasion (TA0005)
ATT&CK techniques: Hide Artifacts: NTFS File Attributes (T1564.004)
Indicator:

Process action type = execution AND target process name = rundll32.exe , mavinject.exe , forfiles.exe , wscript.exe , cscript.exe , mshta.exe , control.exe , sc.exe , regedit.exe , bitsadmin.exe , appvlp.exe , cmd.exe , ftp.exe , bash.exe , regsvr32.exe , regini.exe AND target process cmd =~ :[A-Za-z0-9]{1,}\.(exe|dll|vbs|js|hta|reg|bat|txt|sh|ini|ps1) Host host os = windows

Preventable: yes