Questions tagged [alternative-data-streams]

Windows NTFS feature that allows files to contain more than one stream of data. These streams can be used to hide malicious files behind a legitimate one.

ADS has the ability to fork file data into existing files without affecting their functionality, size, or display to traditional file browsing utilities like dir or Windows Explorer (though dir /R can be used to see ADS).After gaining access to a system a malicious file can be hidden behind a legitimate one.

They are used legitimately by a variety of programs, including native Windows operating system to store file information such as attributes and temporary storage.

5 questions
10
votes
2 answers

How can I identify / discover files hidden with ADS?

ADS, or alternate data streams, were added in to Windows in 1993 (First Windows NT version) as a feature of the new NTFS file system to help support some features of the Mac OS at the time. I like to read about security stuff, and I recently read…
cutrightjm
  • 1,714
  • 4
  • 18
  • 31
6
votes
2 answers

Data Abstraction Layers in Forensic Imaging

I am a bit confused from various sources about the abstraction level and layers that a file resides in forensic imaging. I have found two slightly different explanations: The first one includes a) Physical Layer (sectors,cylinders etc.) b) Data…
4
votes
1 answer

Does anti-virus/security software protect against NTFS ADS?

I know that NTFS has features called ADS which may be used to hide malware. So does antivirus/security software, such as Norton 360, protect against this type of attack?
1
vote
2 answers

How to copy files without copying Alternate Data Streams

I want to backup my infected Windows system's files before formatting it all and reinstalling the system. I would do it from a Linux Live USB. I've heard that one should be careful in copying only the files and not the alternate data streams or they…
1
vote
0 answers

Is is possible to modify the Alternate Data Stream (ADS) in MS Word with Protected View?

Is it possible to modify the Alternate Data Stream (ADS) to prevent .docx to be opened in Protected View for files downloaded from Internet. When is Protected View used? Since Protected View is a read only view, we understand it is not something…
cyzczy
  • 1,518
  • 5
  • 21
  • 34