Fragmentation and Alternate Data Streams: See the Whole NTFS Object
A directory name exposes only part of an NTFS file. Data can occupy non-contiguous extents or named streams, so collection and detection must reason about records, attributes, runs, and execution rather than the default stream alone.
No instructions for hiding, launching, or assembling payloads in streams or fragments are provided.
Logical object, distributed storage
Fragmentation is routine storage behavior. Alternate data streams also support legitimate metadata and application workflows. Risk rises when an unusual named stream in a user-writable or execution-relevant location is created by an untrusted process and followed by decoding, copying, persistence, or execution.
Detection and forensics
- Inventory named streams in startup, profile, download, temporary, and web-content paths.
- Correlate stream creation with process lineage, signer, network origin, and later reads.
- Detect tools that copy only the unnamed stream and create acquisition blind spots.
- Preserve MFT, USN, stream names, sizes, hashes, run lists, ACLs, and Zone metadata.
Use MFTECmd, Velociraptor, Plaso, and Volatility 3. A safe lab can place harmless text in a named stream and verify that inventory and acquisition retain it.
ATT&CK and controls
Alternate streams map to T1564.004 NTFS File Attributes; artifact breakup may overlap T1027. These are capabilities, not CVEs. Use stream-aware backup and collection, application control, endpoint monitoring, least privilege, and behavioral correlation rather than alerting on every stream.