Windows Process Creation: Execution CommandLines Involving NTFS Alternate Data Streams

Alerts on Windows executions whose command lines reference NTFS Alternate Data Streams combined with specific file-data tools.

FreeReviewedSigma · Medium · v1
Product
windows
Category
process_creation
Author
frack113 (SigmaHQ), DRL 1.1
Published
2021-09-01
Updated
2026-07-30

ATT&CK techniques

Defense Evasion
  1. Recon

  2. Resource Dev

  3. Initial Access

  4. Execution

  5. Persistence

  6. Priv Esc

  7. Cred Access

  8. Discovery

  9. Lateral Movement

  10. Collection

  11. C2

  12. Exfiltration

  13. Impact

What it detects

This rule flags Windows process creation events whose command line contains a stream indicator consistent with NTFS Alternate Data Streams (ADS) usage (e.g., the presence of “txt:”). It further narrows matches to common utility execution patterns that can write or retrieve data via files, such as type redirect, makecab, reg export, regedit export, and esentutl operations. Adversaries may use ADS to conceal malicious content within legitimate files and reduce the likelihood of file-based detection, so correlating these command-line patterns is important. Telemetry relied upon is Windows process creation with access to the full CommandLine string.

Related detections9 linkedT1564.004 — drag to rearrange
Suspicious Alternate Data Stream Creation by MuddyWater (via file_event)
Suspicious Command Execution from NTFS Alternate Data Stream via cmd Redirection (via process_creation)
Suspicious Run Key Referencing Alternate Data Stream Payload
macOS chflags Hidden Flag Set via chflags hidden parameter
Windows Process Creation: CLI CommandLine References NTFS ::$index_allocation Stream
Windows Hidden Directory Creation Using NTFS $INDEX_ALLOCATION Stream
Windows rundll32 Launching DLL From Alternate Data Stream (ADS) Paths
Windows suspicious file download URLs using direct IP address with script/binary extensions
Windows Named Pipe Stream Created with Known Hack Tool IMPHASHs
Windows Process Creation: Execution CommandLines Involving NTFS Alternate Data Streams
Pivot detection · T1564.004 · 9 related

Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.