Esc
NTFS File Attributes - T1564.004
(ATT&CK® Technique)
Definition
Adversaries may use NTFS file attributes to hide their malicious data in order to evade detection. Every New Technology File System (NTFS) formatted partition contains a Master File Table (MFT) that maintains a record for every file/directory on the partition. Within MFT entries are file attributes, such as Extended Attributes (EA) and Data [known as Alternate Data Streams (ADSs) when more than one Data attribute is present], that can be used to store arbitrary data (and even complete files).
D3FEND Inferred Relationships
Browse the D3FEND knowledge graph by clicking on the nodes below.