BIOC
Informational
✕
The scripting engine executed code from an Alternate Data Stream (ADS)
Alternate Data Streams (ADSs) are NTFS Master File Table (MFT) data entries that relate to a file, but are separate from its contents. An attacker may try to evade detection by executing malware from the ADS value of a file.
- Module:
- Platform Analytics
- Agent event type:
- Process execution
- Category:
- Evasion
- Status:
- Enabled
ATT&CK tactics: Defense Evasion (TA0005)
ATT&CK techniques: Hide Artifacts: NTFS File Attributes (T1564.004)
Indicator:
Process action type = execution AND target process name = rundll32.exe , mavinject.exe , forfiles.exe , wscript.exe , cscript.exe , mshta.exe , control.exe , sc.exe , regedit.exe , bitsadmin.exe , appvlp.exe , cmd.exe , ftp.exe , bash.exe , regsvr32.exe , regini.exe AND target process cmd =~ :[A-Za-z0-9]{1,}\.(exe|dll|vbs|js|hta|reg|bat|txt|sh|ini|ps1) Host host os = windows
Preventable: yes