Windows Hidden Directory Creation via NTFS $INDEX_ALLOCATION Stream in File Events
Alerts on Windows file events creating hidden NTFS content using the '::$index_allocation' alternate stream.
FreeUnreviewedSigmamediumv1
windows-hidden-directory-creation-via-ntfs-index-allocation-stream-in-file-event-a8f866e1
title: Windows Hidden Directory Creation via NTFS $INDEX_ALLOCATION Stream in File Events
id: 5f9bb9f1-54a0-429e-8e2c-21eccb21c41a
related:
- id: 0900463c-b33b-49a8-be1d-552a3b553dae
type: similar
- id: a8f866e1-bdd4-425e-a27a-37619238d9c7
type: derived
status: test
description: This rule flags file system events where the target filename contains the NTFS alternate data stream suffix '::$index_allocation', indicating creation of a hidden file or directory using the $INDEX_ALLOCATION stream. Attackers may use this technique to reduce visibility and interfere with normal tooling access, supporting stealth objectives. The detection relies on Windows file event telemetry that records the target filename including the alternate stream identifier.
references:
- https://twitter.com/pfiatde/status/1681977680688738305
- https://soroush.me/blog/2010/12/a-dotty-salty-directory-a-secret-place-in-ntfs-for-secret-files/
- https://sec-consult.com/blog/detail/pentesters-windows-ntfs-tricks-collection/
- https://github.com/redcanaryco/atomic-red-team/blob/5c3b23002d2bbede3c07e7307165fc2a235a427d/atomics/T1564.004/T1564.004.md#atomic-test-5---create-hidden-directory-via-index_allocation
- https://learn.microsoft.com/en-us/openspecs/windows_protocols/ms-fscc/c54dec26-1551-4d3a-a0ea-4fa40f848eb3
- https://github.com/SigmaHQ/sigma/blob/master/rules/windows/file/file_event/file_event_win_susp_hidden_dir_index_allocation.yml
author: Scoubi (@ScoubiMtl), Huntrule Team
date: 2023-10-09
tags:
- attack.stealth
- attack.t1564.004
logsource:
product: windows
category: file_event
detection:
selection:
TargetFilename|contains: ::$index_allocation
condition: selection
falsepositives:
- Unlikely
level: medium
license: DRL-1.1
What it detects
This rule flags file system events where the target filename contains the NTFS alternate data stream suffix '::$index_allocation', indicating creation of a hidden file or directory using the $INDEX_ALLOCATION stream. Attackers may use this technique to reduce visibility and interfere with normal tooling access, supporting stealth objectives. The detection relies on Windows file event telemetry that records the target filename including the alternate stream identifier.
Known false positives
- Unlikely
Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.