[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$fgE7KBOna50JWlQ0iGwi8kb1MesERSe48Xa7aAMEpRu0":3},{"id":4,"question":5,"answer":6,"answerHtml":7,"slug":8,"keywords":9,"article":10,"status":34,"aiModel":39,"aiConfidence":39,"updatedAt":49,"createdAt":49,"_status":48},262,"How can special Alternative Data Streams (ADS) bypass conventional detection tools like ADSCheck.exe and streams.exe?","Special ADS created with unusual filenames such as `...` (three dots), COM device names (e.g., `COM1`), or the disk root (`C:\\`) are not listed by `dir \u002Fr` or detected by tools like ADSCheck.exe and streams.exe. For example, using `type putty.exe > ...:putty.exe` hides the ADS entirely from these scanners. These special names exploit Windows naming conventions to evade discovery, as detailed in the [article](\u002Fnews\u002Fadvanced-exploitation-techniques-for-hidden-alternative-data-streams).","\u003Cp>Special ADS created with unusual filenames such as `...` (three dots), COM device names (e.g., `COM1`), or the disk root (`C:\\`) are not listed by `dir \u002Fr` or detected by tools like ADSCheck.exe and streams.exe. For example, using `type putty.exe &gt; ...:putty.exe` hides the ADS entirely from these scanners. These special names exploit Windows naming conventions to evade discovery, as detailed in the [article](\u002Fnews\u002Fadvanced-exploitation-techniques-for-hidden-alternative-data-streams).\u003C\u002Fp>\u003Cp>\u003Ca href=\"\u002Fnews\u002Fadvanced-exploitation-techniques-for-hidden-alternative-data-streams\">Read the related One Day Sec article\u003C\u002Fa>\u003C\u002Fp>","how-can-special-alternative-data-streams-ads-bypass-conventional-detection-tools-1777484357316","ADS detection bypass, special filenames, COM device names, disk root ADS, ADSCheck, streams.exe",{"id":11,"title":12,"slug":13,"description":14,"content":15,"contentHtml":30,"cover":31,"author":32,"views":19,"readingTime":33,"status":34,"publishedAt":35,"seo":36,"tags":41,"qaPairs":42,"meta":45,"updatedAt":46,"createdAt":47,"_status":48},68,"Advanced Exploitation Techniques for Hidden Alternative Data Streams","advanced-exploitation-techniques-for-hidden-alternative-data-streams","Learn advanced techniques for exploiting and hiding Alternative Data Streams (ADS) in NTFS, including bypassing detection tools and executing payloads via WMI and PowerShell.",{"root":16},{"type":17,"format":18,"indent":19,"version":20,"children":21,"direction":29},"root","",0,1,[22],{"type":23,"format":18,"indent":19,"version":20,"children":24,"direction":29},"paragraph",[25],{"mode":26,"text":27,"type":28,"style":18,"detail":19,"format":19,"version":20},"normal","\u003Chtml>\u003Chead>\u003C\u002Fhead>\u003Cbody>\u003Ch2>0x00 Preface\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>In penetration testing, ADS (Alternative Data Stream) is commonly used to hide payloads within files. The greatest advantage of this method is that it does not affect the file size, making it difficult for ordinary users to detect.\u003C\u002Fp>\u003Cp>To address this, Microsoft provides the \"dir \u002Fr\" command to view ADS in files. Additionally, systems after Windows XP prohibit users from directly executing programs from ADS, limiting its exploitation.\u003C\u002Fp>\u003Cp>However, through some special methods and techniques, we can better hide ADS and even execute programs directly from ADS :)\u003C\u002Fp>\u003Cp>\u003Cstrong>Note:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>The original intention of writing this article was inspired by an interesting piece I came across, authored by lex Inführ, available at the following address:\u003C\u002Fp>\u003Cp>http:\u002F\u002Finsert-script.blogspot.co.at\u002F2012\u002F11\u002Fhidden-alternative-data-streams.html\u003C\u002Fp>\u003Cp>That article introduces some techniques to bypass ADS detection tools and provides a method to execute ADS via WMI.\u003C\u002Fp>\u003Cp>This article will expand on the exploitation techniques of ADS based on lex Inführ's work, incorporating my research insights, and share how to clean up these special ADS to help enhance everyone's understanding of ADS.\u003C\u002Fp>\u003Ch2>0x01 Introduction\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>This article will cover the following topics:\u003C\u002Fp>\u003Cul>\u003Cli>Conventional Exploitation Methods for ADS\u003C\u002Fli>\u003Cli>ADS Regular Detection Tools\u003C\u002Fli>\u003Cli>Bypassing Detection Tools with Special ADS\u003C\u002Fli>\u003Cli>Clearing Special ADS\u003C\u002Fli>\u003Cli>Defense Recommendations\u003C\u002Fli>\u003C\u002Ful>\u003Ch2>0x02 Regular Exploitation\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Ch3>ADS:\u003C\u002Fh3>\u003Cp>Applicable to NTFS file system. Basic knowledge can be referenced in the following article:\u003C\u002Fp>\u003Cp>http:\u002F\u002Fwww.freebuf.com\u002Farticles\u002F73270.html\u003C\u002Fp>\u003Ch3>Creating ADS:\u003C\u002Fh3>\u003Cp>For files, command line:\u003C\u002Fp>\u003Cp>echo test1 &gt; test.txt:ThisIsAnADS\u003C\u002Fp>\u003Cp>After successful creation, the file size of test.txt remains unchanged\u003C\u002Fp>\u003Cp>For folders, command line:\u003C\u002Fp>\u003Cp>echo test1 &gt; c:\\test\\ads\\1:ThisIsAnADS\u003C\u002Fp>\u003Cp>\u003Cstrong>Note:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>Absolute path required\u003C\u002Fp>\u003Ch3>View ADS in files:\u003C\u002Fh3>\u003Cp>Command line:\u003C\u002Fp>\u003Cp>dir \u002Fr\u003C\u002Fp>\u003Cp>As shown in the figure\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fuploads\u002Fdocx_image_1770018754552_0_a6633d7acb.jpeg\">\u003C\u002Fp>\u003Cp>Can obtain ADS information contained in folders and files\u003C\u002Fp>\u003Ch3>View ADS content:\u003C\u002Fh3>\u003Cp>Command line:\u003C\u002Fp>\u003Cp>more &lt; test.txt:ThisIsAnADS\u003C\u002Fp>\u003Cp>As shown in the figure below, obtain the specific content of ADS\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fuploads\u002Fdocx_image_1770018766228_1_531745a65a.jpeg\">\u003C\u002Fp>\u003Ch3>Delete ADS:\u003C\u002Fh3>\u003Cp>Command line:\u003C\u002Fp>\u003Cp>more &lt; test.txt &gt; testcopy.txt\u003C\u002Fp>\u003Cp>Using the more command to view the main data stream of a file and outputting it can indirectly achieve ADS deletion.\u003C\u002Fp>\u003Cp>As shown below, testcopy.txt does not contain extra ADS.\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fuploads\u002Fdocx_image_1770018783001_2_bc3323c3e1.jpeg\">\u003C\u002Fp>\u003Cp>\u003Cstrong>Note:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>The more command truncates and displays output screen by screen when showing long data, which contains a bug: if the file is too large, causing the more command to require pagination, it can lead to incomplete data display and file generation failure.\u003C\u002Fp>\u003Ch2>0x03 ADS Execution\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Ch3>1. Via WMI\u003C\u002Fh3>\u003Cp>Command line:\u003C\u002Fp>\u003Cp>type putty.exe &gt; test.txt:putty.exe\u003C\u002Fp>\u003Cp>wmic process call create c:\\test\\test.txt:putty.exe\u003C\u002Fp>\u003Cp>As shown in the figure\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fuploads\u002Fdocx_image_1770018792281_3_aabdd47fd8.jpeg\">\u003C\u002Fp>\u003Cp>After program execution, the process name is test.txt:putty.exe\u003C\u002Fp>\u003Ch3>2. Via PowerShell\u003C\u002Fh3>\u003Cp>Code as follows:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>$ps = new-object System.Diagnostics.Process\u003Cbr>$ps.StartInfo.Filename= \"c:\\test\\test.txt:putty.exe\"\u003Cbr>$ps.StartInfo.RedirectStandardOutput = $True\u003Cbr>$ps.StartInfo.UseShellExecute = $False\u003Cbr>$ps.start()\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Ch2>0x04 Conventional Detection Tools\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Ch3>1. ADSCheck.exe\u003C\u002Fh3>\u003Cp>\u003Cstrong>Download link:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>https:\u002F\u002Fsourceforge.net\u002Fprojects\u002Fadscheck\u002F\u003C\u002Fp>\u003Cp>\u003Cstrong>View ADS:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>Can view all files under the specified folder\u003C\u002Fp>\u003Cp>Command:\u003C\u002Fp>\u003Cp>ADSCheck.exe c:\\test\\ads\u003C\u002Fp>\u003Cp>As shown in the figure\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fuploads\u002Fdocx_image_1770018803131_4_0af2711e12.jpeg\">\u003C\u002Fp>\u003Cp>\u003Cstrong>Delete ADS:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>All ADS under the specified path can be deleted\u003C\u002Fp>\u003Cp>Command:\u003C\u002Fp>\u003Cp>ADSCheck.exe c:\\test\\ads \u002Fd\u003C\u002Fp>\u003Cp>As shown in the figure\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fuploads\u002Fdocx_image_1770018809626_5_466fe59bc0.jpeg\">\u003C\u002Fp>\u003Ch3>2、Streams.exe\u003C\u002Fh3>\u003Cp>\u003Cstrong>Download address:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>https:\u002F\u002Ftechnet.microsoft.com\u002Fen-us\u002Fsysinternals\u002Fstreams.aspx\u003C\u002Fp>\u003Cp>\u003Cstrong>View ADS:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>View a single file\u003C\u002Fp>\u003Cp>Command:\u003C\u002Fp>\u003Cp>streams.exe c:\\test\\ads\\test.txt\u003C\u002Fp>\u003Cp>As shown in the figure\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fuploads\u002Fdocx_image_1770018815873_6_114f28fcb8.jpeg\">\u003C\u002Fp>\u003Cp>\u003Cstrong>Delete ADS:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>Delete ADS for a single file\u003C\u002Fp>\u003Cp>Command:\u003C\u002Fp>\u003Cp>streams.exe -d c:\\test\\ads\\test.txt\u003C\u002Fp>\u003Cp>As shown in the figure\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fuploads\u002Fdocx_image_1770018822179_7_9dddf64612.jpeg\">\u003C\u002Fp>\u003Ch3>Example test:\u003C\u002Fh3>\u003Cp>When opening a file downloaded by the browser, a prompt dialog appears\u003C\u002Fp>\u003Cp>As shown in the figure\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fuploads\u002Fdocx_image_1770018826728_8_29af204515.jpeg\">\u003C\u002Fp>\u003Cp>\u003Cstrong>Reason:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>Downloaded files are automatically added with adsZone.Identifier:$DATA\u003C\u002Fp>\u003Cp>\u003Cstrong>Verification:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>View ADS:\u003C\u002Fp>\u003Cp>more &lt; putty_download.exe:Zone.Identifier:$DATA\u003C\u002Fp>\u003Cp>Content obtained as follows:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>[ZoneTransfer]\u003Cbr>ZoneId=3\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>Remove ADS:\u003C\u002Fp>\u003Cp>Cannot use the more command because putty_download.exe is too large, requiring paged display, causing file generation to fail\u003C\u002Fp>\u003Cp>Can use streams.exe\u003C\u002Fp>\u003Cp>After removing ADS, opening the file no longer prompts with a dialog box\u003C\u002Fp>\u003Ch2>0x05 Special ADS\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Ch3>1. ...file\u003C\u002Fh3>\u003Cp>Create special file...\u003C\u002Fp>\u003Cp>Command as follows:\u003C\u002Fp>\u003Cp>type putty.exe &gt; ...:putty.exe\u003C\u002Fp>\u003Cp>wmic process call create c:\\test\\ads\\...:putty.exe\u003C\u002Fp>\u003Cp>putty.exe executed successfully, process name is ...:putty.exe\u003C\u002Fp>\u003Cp>\u003Cstrong>Special features:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>(1) ADS is hidden\u003C\u002Fp>\u003Cul>\u003Cli>dir \u002Fr cannot query it\u003C\u002Fli>\u003Cli>Tools ADSCheck.exe and streams.exe show no ADS exists\u003C\u002Fli>\u003C\u002Ful>\u003Cp>As shown in the figure\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fuploads\u002Fdocx_image_1770018830803_9_617aa7b63f.jpeg\">\u003C\u002Fp>\u003Cp>(2) The file cannot be deleted\u003C\u002Fp>\u003Cp>Various methods attempted, unable to delete, as shown in the figure\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fuploads\u002Fdocx_image_1770018834401_10_dc42fca3fe.jpeg\">\u003C\u002Fp>\u003Ch3>2. Special COM file\u003C\u002Fh3>\u003Cp>Create a special name file COM1\u003C\u002Fp>\u003Cp>\u003Cstrong>Note:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>After testing, the system currently supports file names from COM1 to COM9\u003C\u002Fp>\u003Cp>The prefix \\\\.\\ must be included, otherwise the system will prompt that the specified file cannot be found\u003C\u002Fp>\u003Cp>\u003Cstrong>Supplement 1:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>The special name nul has the same effect, this method was tested and confirmed by Evi1cg\u003C\u002Fp>\u003Cp>\u003Cstrong>Supplement 2:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>Other special file formats can also hide ADS, including the following suffix formats:\u003C\u002Fp>\u003Cp>CON, AUX, PRN, LPT1, LPT2, LPT3, LPT4, LPT5, LPT6, LPT7, LPT8, LPT9\u003C\u002Fp>\u003Cp>eg:\u003C\u002Fp>\u003Cp>type putty.exe &gt; \\\\.\\C:\\test\\ads\\LPT4:putty.exe\u003C\u002Fp>\u003Cp>\u003Cstrong>Note:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>For more special file names, refer to:\u003C\u002Fp>\u003Cp>https:\u002F\u002Fdocs.microsoft.com\u002Fen-us\u002Fwindows\u002Fdesktop\u002FFileIO\u002Fnaming-a-file#naming-conventions\u003C\u002Fp>\u003Cp>\u003Cstrong>Supplement 3:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>The prefix \\\\?\\ can also be used, with the same effect\u003C\u002Fp>\u003Cp>Command as follows:\u003C\u002Fp>\u003Cp>type putty.exe &gt; \\\\.\\C:\\test\\ads\\COM1:putty.exe\u003C\u002Fp>\u003Cp>wmic process call create \\\\.\\C:\\test\\ads\\COM1:putty.exe\u003C\u002Fp>\u003Cp>\u003Cstrong>Note:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>*Executing wmic process call create c:\\test\\ads\\COM1:putty.exe does not run the program*\u003C\u002Fp>\u003Cp>putty.exe successfully executed, process name is COM1:putty.exe\u003C\u002Fp>\u003Cp>\u003Cstrong>Special aspects:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>(1) ADS is hidden\u003C\u002Fp>\u003Cul>\u003Cli>dir \u002Fr cannot query it\u003C\u002Fli>\u003Cli>Tools ADSCheck.exe and streams.exe show no ADS exists\u003C\u002Fli>\u003C\u002Ful>\u003Cp>(2) Cannot be directly deleted\u003C\u002Fp>\u003Ch3>3. Disk root directory\u003C\u002Fh3>\u003Cp>Administrator privileges\u003C\u002Fp>\u003Cp>type putty.exe &gt;C:\\:putty.exe\u003C\u002Fp>\u003Cp>wmic process call create C:\\:putty.exe\u003C\u002Fp>\u003Cp>putty.exe successfully executed, process name is :putty.exe\u003C\u002Fp>\u003Cp>\u003Cstrong>Special features:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>(1) ADS is hidden\u003C\u002Fp>\u003Cul>\u003Cli>dir \u002Fr cannot find it\u003C\u002Fli>\u003Cli>Use streams.exe to view\u003C\u002Fli>\u003C\u002Ful>\u003Cp>(2) Cannot be directly deleted\u003C\u002Fp>\u003Ch2>0x06 Clearing special ADS\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Ch3>1、...file\u003C\u002Fh3>\u003Cp>Method 1:\u003C\u002Fp>\u003Cp>Delete all files in the directory:\u003C\u002Fp>\u003Cp>del *.*\u003C\u002Fp>\u003Cp>But not practical\u003C\u002Fp>\u003Cp>Method 2:\u003C\u002Fp>\u003Cp>Use short filenames\u003C\u002Fp>\u003Cp>dir \u002Fx\u003C\u002Fp>\u003Cp>As shown in the figure\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fuploads\u002Fdocx_image_1770018836039_11_648fb74519.jpeg\">\u003C\u002Fp>\u003Cp>Find the short file name corresponding to the ... file as A535~1\u003C\u002Fp>\u003Cp>Command line:\u003C\u002Fp>\u003Cp>del A535~1\u003C\u002Fp>\u003Cp>Successfully deleted\u003C\u002Fp>\u003Ch3>2. Special COM file\u003C\u002Fh3>\u003Cp>Command line:\u003C\u002Fp>\u003Cp>del \\\\.\\C:\\test\\ads\\COM1\u003C\u002Fp>\u003Ch3>3. Disk root directory\u003C\u002Fh3>\u003Cp>Using streams.exe\u003C\u002Fp>\u003Cp>Administrator privileges:\u003C\u002Fp>\u003Cp>streams.exe -d C:\\\u003C\u002Fp>\u003Ch2>0x07 Defense Recommendations\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>For users, if they discover files with special names in the system that cannot be deleted, they should be vigilant, as these may contain payloads.\u003C\u002Fp>\u003Cp>Referencing this article, the special files and their removal methods are as follows:\u003C\u002Fp>\u003Cp>(1) ...\u003C\u002Fp>\u003Cp>Delete using short filenames.\u003C\u002Fp>\u003Cp>(2) COM1-COM9\u003C\u002Fp>\u003Cp>del \\\\.\\C:\\test\\ads\\COM1\u003C\u002Fp>\u003Cp>(3) Disk root directory\u003C\u002Fp>\u003Cp>View and delete using streams.exe.\u003C\u002Fp>\u003Ch2>0x08 Summary\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>This article introduces advanced techniques for hiding ADS, shares specific removal methods and defense recommendations in combination with attack methods, hoping to assist everyone.\u003C\u002Fp>\u003C\u002Fbody>\u003C\u002Fhtml>","text","ltr","\u003Chtml>\u003Chead>\u003C\u002Fhead>\u003Cbody>\u003Ch2>0x00 Preface\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>In penetration testing, ADS (Alternative Data Stream) is commonly used to hide payloads within files. The greatest advantage of this method is that it does not affect the file size, making it difficult for ordinary users to detect.\u003C\u002Fp>\u003Cp>To address this, Microsoft provides the \"dir \u002Fr\" command to view ADS in files. Additionally, systems after Windows XP prohibit users from directly executing programs from ADS, limiting its exploitation.\u003C\u002Fp>\u003Cp>However, through some special methods and techniques, we can better hide ADS and even execute programs directly from ADS :)\u003C\u002Fp>\u003Cp>\u003Cstrong>Note:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>The original intention of writing this article was inspired by an interesting piece I came across, authored by lex Inführ, available at the following address:\u003C\u002Fp>\u003Cp>http:\u002F\u002Finsert-script.blogspot.co.at\u002F2012\u002F11\u002Fhidden-alternative-data-streams.html\u003C\u002Fp>\u003Cp>That article introduces some techniques to bypass ADS detection tools and provides a method to execute ADS via WMI.\u003C\u002Fp>\u003Cp>This article will expand on the exploitation techniques of ADS based on lex Inführ's work, incorporating my research insights, and share how to clean up these special ADS to help enhance everyone's understanding of ADS.\u003C\u002Fp>\u003Ch2>0x01 Introduction\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>This article will cover the following topics:\u003C\u002Fp>\u003Cul>\u003Cli>Conventional Exploitation Methods for ADS\u003C\u002Fli>\u003Cli>ADS Regular Detection Tools\u003C\u002Fli>\u003Cli>Bypassing Detection Tools with Special ADS\u003C\u002Fli>\u003Cli>Clearing Special ADS\u003C\u002Fli>\u003Cli>Defense Recommendations\u003C\u002Fli>\u003C\u002Ful>\u003Ch2>0x02 Regular Exploitation\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Ch3>ADS:\u003C\u002Fh3>\u003Cp>Applicable to NTFS file system. Basic knowledge can be referenced in the following article:\u003C\u002Fp>\u003Cp>http:\u002F\u002Fwww.freebuf.com\u002Farticles\u002F73270.html\u003C\u002Fp>\u003Ch3>Creating ADS:\u003C\u002Fh3>\u003Cp>For files, command line:\u003C\u002Fp>\u003Cp>echo test1 &gt; test.txt:ThisIsAnADS\u003C\u002Fp>\u003Cp>After successful creation, the file size of test.txt remains unchanged\u003C\u002Fp>\u003Cp>For folders, command line:\u003C\u002Fp>\u003Cp>echo test1 &gt; c:\\test\\ads\\1:ThisIsAnADS\u003C\u002Fp>\u003Cp>\u003Cstrong>Note:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>Absolute path required\u003C\u002Fp>\u003Ch3>View ADS in files:\u003C\u002Fh3>\u003Cp>Command line:\u003C\u002Fp>\u003Cp>dir \u002Fr\u003C\u002Fp>\u003Cp>As shown in the figure\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fapi\u002Fmedia\u002Ffile\u002Fdocx_image_1770018754552_0_a6633d7acb-1.jpeg\">\u003C\u002Fp>\u003Cp>Can obtain ADS information contained in folders and files\u003C\u002Fp>\u003Ch3>View ADS content:\u003C\u002Fh3>\u003Cp>Command line:\u003C\u002Fp>\u003Cp>more &lt; test.txt:ThisIsAnADS\u003C\u002Fp>\u003Cp>As shown in the figure below, obtain the specific content of ADS\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fapi\u002Fmedia\u002Ffile\u002Fdocx_image_1770018766228_1_531745a65a-1.jpeg\">\u003C\u002Fp>\u003Ch3>Delete ADS:\u003C\u002Fh3>\u003Cp>Command line:\u003C\u002Fp>\u003Cp>more &lt; test.txt &gt; testcopy.txt\u003C\u002Fp>\u003Cp>Using the more command to view the main data stream of a file and outputting it can indirectly achieve ADS deletion.\u003C\u002Fp>\u003Cp>As shown below, testcopy.txt does not contain extra ADS.\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fapi\u002Fmedia\u002Ffile\u002Fdocx_image_1770018783001_2_bc3323c3e1-1.jpeg\">\u003C\u002Fp>\u003Cp>\u003Cstrong>Note:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>The more command truncates and displays output screen by screen when showing long data, which contains a bug: if the file is too large, causing the more command to require pagination, it can lead to incomplete data display and file generation failure.\u003C\u002Fp>\u003Ch2>0x03 ADS Execution\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Ch3>1. Via WMI\u003C\u002Fh3>\u003Cp>Command line:\u003C\u002Fp>\u003Cp>type putty.exe &gt; test.txt:putty.exe\u003C\u002Fp>\u003Cp>wmic process call create c:\\test\\test.txt:putty.exe\u003C\u002Fp>\u003Cp>As shown in the figure\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fapi\u002Fmedia\u002Ffile\u002Fdocx_image_1770018792281_3_aabdd47fd8-1.jpeg\">\u003C\u002Fp>\u003Cp>After program execution, the process name is test.txt:putty.exe\u003C\u002Fp>\u003Ch3>2. Via PowerShell\u003C\u002Fh3>\u003Cp>Code as follows:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>$ps = new-object System.Diagnostics.Process\u003Cbr>$ps.StartInfo.Filename= \"c:\\test\\test.txt:putty.exe\"\u003Cbr>$ps.StartInfo.RedirectStandardOutput = $True\u003Cbr>$ps.StartInfo.UseShellExecute = $False\u003Cbr>$ps.start()\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Ch2>0x04 Conventional Detection Tools\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Ch3>1. ADSCheck.exe\u003C\u002Fh3>\u003Cp>\u003Cstrong>Download link:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>https:\u002F\u002Fsourceforge.net\u002Fprojects\u002Fadscheck\u002F\u003C\u002Fp>\u003Cp>\u003Cstrong>View ADS:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>Can view all files under the specified folder\u003C\u002Fp>\u003Cp>Command:\u003C\u002Fp>\u003Cp>ADSCheck.exe c:\\test\\ads\u003C\u002Fp>\u003Cp>As shown in the figure\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fapi\u002Fmedia\u002Ffile\u002Fdocx_image_1770018803131_4_0af2711e12-1.jpeg\">\u003C\u002Fp>\u003Cp>\u003Cstrong>Delete ADS:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>All ADS under the specified path can be deleted\u003C\u002Fp>\u003Cp>Command:\u003C\u002Fp>\u003Cp>ADSCheck.exe c:\\test\\ads \u002Fd\u003C\u002Fp>\u003Cp>As shown in the figure\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fapi\u002Fmedia\u002Ffile\u002Fdocx_image_1770018809626_5_466fe59bc0-1.jpeg\">\u003C\u002Fp>\u003Ch3>2、Streams.exe\u003C\u002Fh3>\u003Cp>\u003Cstrong>Download address:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>https:\u002F\u002Ftechnet.microsoft.com\u002Fen-us\u002Fsysinternals\u002Fstreams.aspx\u003C\u002Fp>\u003Cp>\u003Cstrong>View ADS:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>View a single file\u003C\u002Fp>\u003Cp>Command:\u003C\u002Fp>\u003Cp>streams.exe c:\\test\\ads\\test.txt\u003C\u002Fp>\u003Cp>As shown in the figure\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fapi\u002Fmedia\u002Ffile\u002Fdocx_image_1770018815873_6_114f28fcb8-1.jpeg\">\u003C\u002Fp>\u003Cp>\u003Cstrong>Delete ADS:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>Delete ADS for a single file\u003C\u002Fp>\u003Cp>Command:\u003C\u002Fp>\u003Cp>streams.exe -d c:\\test\\ads\\test.txt\u003C\u002Fp>\u003Cp>As shown in the figure\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fapi\u002Fmedia\u002Ffile\u002Fdocx_image_1770018822179_7_9dddf64612-1.jpeg\">\u003C\u002Fp>\u003Ch3>Example test:\u003C\u002Fh3>\u003Cp>When opening a file downloaded by the browser, a prompt dialog appears\u003C\u002Fp>\u003Cp>As shown in the figure\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fapi\u002Fmedia\u002Ffile\u002Fdocx_image_1770018826728_8_29af204515-1.jpeg\">\u003C\u002Fp>\u003Cp>\u003Cstrong>Reason:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>Downloaded files are automatically added with adsZone.Identifier:$DATA\u003C\u002Fp>\u003Cp>\u003Cstrong>Verification:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>View ADS:\u003C\u002Fp>\u003Cp>more &lt; putty_download.exe:Zone.Identifier:$DATA\u003C\u002Fp>\u003Cp>Content obtained as follows:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>[ZoneTransfer]\u003Cbr>ZoneId=3\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>Remove ADS:\u003C\u002Fp>\u003Cp>Cannot use the more command because putty_download.exe is too large, requiring paged display, causing file generation to fail\u003C\u002Fp>\u003Cp>Can use streams.exe\u003C\u002Fp>\u003Cp>After removing ADS, opening the file no longer prompts with a dialog box\u003C\u002Fp>\u003Ch2>0x05 Special ADS\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Ch3>1. ...file\u003C\u002Fh3>\u003Cp>Create special file...\u003C\u002Fp>\u003Cp>Command as follows:\u003C\u002Fp>\u003Cp>type putty.exe &gt; ...:putty.exe\u003C\u002Fp>\u003Cp>wmic process call create c:\\test\\ads\\...:putty.exe\u003C\u002Fp>\u003Cp>putty.exe executed successfully, process name is ...:putty.exe\u003C\u002Fp>\u003Cp>\u003Cstrong>Special features:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>(1) ADS is hidden\u003C\u002Fp>\u003Cul>\u003Cli>dir \u002Fr cannot query it\u003C\u002Fli>\u003Cli>Tools ADSCheck.exe and streams.exe show no ADS exists\u003C\u002Fli>\u003C\u002Ful>\u003Cp>As shown in the figure\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fapi\u002Fmedia\u002Ffile\u002Fdocx_image_1770018830803_9_617aa7b63f-1.jpeg\">\u003C\u002Fp>\u003Cp>(2) The file cannot be deleted\u003C\u002Fp>\u003Cp>Various methods attempted, unable to delete, as shown in the figure\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fapi\u002Fmedia\u002Ffile\u002Fdocx_image_1770018834401_10_dc42fca3fe-1.jpeg\">\u003C\u002Fp>\u003Ch3>2. Special COM file\u003C\u002Fh3>\u003Cp>Create a special name file COM1\u003C\u002Fp>\u003Cp>\u003Cstrong>Note:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>After testing, the system currently supports file names from COM1 to COM9\u003C\u002Fp>\u003Cp>The prefix \\\\.\\ must be included, otherwise the system will prompt that the specified file cannot be found\u003C\u002Fp>\u003Cp>\u003Cstrong>Supplement 1:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>The special name nul has the same effect, this method was tested and confirmed by Evi1cg\u003C\u002Fp>\u003Cp>\u003Cstrong>Supplement 2:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>Other special file formats can also hide ADS, including the following suffix formats:\u003C\u002Fp>\u003Cp>CON, AUX, PRN, LPT1, LPT2, LPT3, LPT4, LPT5, LPT6, LPT7, LPT8, LPT9\u003C\u002Fp>\u003Cp>eg:\u003C\u002Fp>\u003Cp>type putty.exe &gt; \\\\.\\C:\\test\\ads\\LPT4:putty.exe\u003C\u002Fp>\u003Cp>\u003Cstrong>Note:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>For more special file names, refer to:\u003C\u002Fp>\u003Cp>https:\u002F\u002Fdocs.microsoft.com\u002Fen-us\u002Fwindows\u002Fdesktop\u002FFileIO\u002Fnaming-a-file#naming-conventions\u003C\u002Fp>\u003Cp>\u003Cstrong>Supplement 3:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>The prefix \\\\?\\ can also be used, with the same effect\u003C\u002Fp>\u003Cp>Command as follows:\u003C\u002Fp>\u003Cp>type putty.exe &gt; \\\\.\\C:\\test\\ads\\COM1:putty.exe\u003C\u002Fp>\u003Cp>wmic process call create \\\\.\\C:\\test\\ads\\COM1:putty.exe\u003C\u002Fp>\u003Cp>\u003Cstrong>Note:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>*Executing wmic process call create c:\\test\\ads\\COM1:putty.exe does not run the program*\u003C\u002Fp>\u003Cp>putty.exe successfully executed, process name is COM1:putty.exe\u003C\u002Fp>\u003Cp>\u003Cstrong>Special aspects:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>(1) ADS is hidden\u003C\u002Fp>\u003Cul>\u003Cli>dir \u002Fr cannot query it\u003C\u002Fli>\u003Cli>Tools ADSCheck.exe and streams.exe show no ADS exists\u003C\u002Fli>\u003C\u002Ful>\u003Cp>(2) Cannot be directly deleted\u003C\u002Fp>\u003Ch3>3. Disk root directory\u003C\u002Fh3>\u003Cp>Administrator privileges\u003C\u002Fp>\u003Cp>type putty.exe &gt;C:\\:putty.exe\u003C\u002Fp>\u003Cp>wmic process call create C:\\:putty.exe\u003C\u002Fp>\u003Cp>putty.exe successfully executed, process name is :putty.exe\u003C\u002Fp>\u003Cp>\u003Cstrong>Special features:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>(1) ADS is hidden\u003C\u002Fp>\u003Cul>\u003Cli>dir \u002Fr cannot find it\u003C\u002Fli>\u003Cli>Use streams.exe to view\u003C\u002Fli>\u003C\u002Ful>\u003Cp>(2) Cannot be directly deleted\u003C\u002Fp>\u003Ch2>0x06 Clearing special ADS\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Ch3>1、...file\u003C\u002Fh3>\u003Cp>Method 1:\u003C\u002Fp>\u003Cp>Delete all files in the directory:\u003C\u002Fp>\u003Cp>del *.*\u003C\u002Fp>\u003Cp>But not practical\u003C\u002Fp>\u003Cp>Method 2:\u003C\u002Fp>\u003Cp>Use short filenames\u003C\u002Fp>\u003Cp>dir \u002Fx\u003C\u002Fp>\u003Cp>As shown in the figure\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fapi\u002Fmedia\u002Ffile\u002Fdocx_image_1770018836039_11_648fb74519-1.jpeg\">\u003C\u002Fp>\u003Cp>Find the short file name corresponding to the ... file as A535~1\u003C\u002Fp>\u003Cp>Command line:\u003C\u002Fp>\u003Cp>del A535~1\u003C\u002Fp>\u003Cp>Successfully deleted\u003C\u002Fp>\u003Ch3>2. Special COM file\u003C\u002Fh3>\u003Cp>Command line:\u003C\u002Fp>\u003Cp>del \\\\.\\C:\\test\\ads\\COM1\u003C\u002Fp>\u003Ch3>3. Disk root directory\u003C\u002Fh3>\u003Cp>Using streams.exe\u003C\u002Fp>\u003Cp>Administrator privileges:\u003C\u002Fp>\u003Cp>streams.exe -d C:\\\u003C\u002Fp>\u003Ch2>0x07 Defense Recommendations\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>For users, if they discover files with special names in the system that cannot be deleted, they should be vigilant, as these may contain payloads.\u003C\u002Fp>\u003Cp>Referencing this article, the special files and their removal methods are as follows:\u003C\u002Fp>\u003Cp>(1) ...\u003C\u002Fp>\u003Cp>Delete using short filenames.\u003C\u002Fp>\u003Cp>(2) COM1-COM9\u003C\u002Fp>\u003Cp>del \\\\.\\C:\\test\\ads\\COM1\u003C\u002Fp>\u003Cp>(3) Disk root directory\u003C\u002Fp>\u003Cp>View and delete using streams.exe.\u003C\u002Fp>\u003Ch2>0x08 Summary\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>This article introduces advanced techniques for hiding ADS, shares specific removal methods and defense recommendations in combination with attack methods, hoping to assist everyone.\u003C\u002Fp>\u003C\u002Fbody>\u003C\u002Fhtml>",1477,"Onedaysec",5,"published","2026-02-02T08:06:59.473Z",{"title":37,"description":14,"keywords":38,"ogImage":39,"canonicalUrl":39,"noIndex":40},"Advanced Exploitation Techniques for Hidden Alternative Data Streams (ADS)","ADS exploitation, Alternative Data Streams, NTFS security, penetration testing, hidden payloads, WMI execution, PowerShell ADS, detection bypass, ADS cleanup, Windows security",null,false,[],{"docs":43,"hasNextPage":40},[4,44],261,{"title":39,"description":39,"image":39},"2026-07-24T15:37:14.528Z","2026-07-23T16:01:17.422Z","draft","2026-07-23T16:04:53.408Z"]