Windows Executable Hidden in NTFS Alternate Data Stream via Imphash Marker

Alerts on NTFS ADS creation where the stream hash includes a non-null IMPHASH marker, consistent with hidden executables.

FreeUnreviewedSigmamediumv1
title: Windows Executable Hidden in NTFS Alternate Data Stream via Imphash Marker
id: c778d13a-96dc-4548-95a2-8e73490ea58e
status: test
description: This rule flags creation of an NTFS Alternate Data Stream whose recorded hash field contains an "IMPHASH=" marker and is not the all-zero placeholder value. Attackers can use ADS to hide or stage executables within files without obvious on-disk artifacts, leveraging stealth techniques. The detection relies on stream-creation telemetry that includes a hash value with imphash tagging (e.g., from Sysmon or equivalent tooling).
references:
  - https://twitter.com/0xrawsec/status/1002478725605273600?s=21
  - https://github.com/SigmaHQ/sigma/blob/master/rules/windows/create_stream_hash/create_stream_hash_ads_executable.yml
author: Florian Roth (Nextron Systems), @0xrawsec, Huntrule Team
date: 2018-06-03
modified: 2023-02-10
tags:
  - attack.stealth
  - attack.s0139
  - attack.t1564.004
logsource:
  product: windows
  category: create_stream_hash
  definition: "Requirements: Sysmon or equivalent configured with Imphash logging"
detection:
  selection:
    Hash|contains: IMPHASH=
  filter_main_null:
    Hash|contains: IMPHASH=00000000000000000000000000000000
  condition: selection and not 1 of filter_main_*
falsepositives:
  - This rule isn't looking for any particular binary characteristics. As legitimate installers and programs were seen embedding hidden binaries in their ADS. Some false positives are expected from browser processes and similar.
level: medium
license: DRL-1.1
related:
  - id: b69888d4-380c-45ce-9cf9-d9ce46e67821
    type: derived

What it detects

This rule flags creation of an NTFS Alternate Data Stream whose recorded hash field contains an "IMPHASH=" marker and is not the all-zero placeholder value. Attackers can use ADS to hide or stage executables within files without obvious on-disk artifacts, leveraging stealth techniques. The detection relies on stream-creation telemetry that includes a hash value with imphash tagging (e.g., from Sysmon or equivalent tooling).

Known false positives

  • This rule isn't looking for any particular binary characteristics. As legitimate installers and programs were seen embedding hidden binaries in their ADS. Some false positives are expected from browser processes and similar.

Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.