← ./resources / blog

Fragmentation and Alternate Data Streams: See the Whole NTFS Object

A directory name exposes only part of an NTFS file. Data can occupy non-contiguous extents or named streams, so collection and detection must reason about records, attributes, runs, and execution rather than the default stream alone.

Defensive scope

No instructions for hiding, launching, or assembling payloads in streams or fragments are provided.

Logical object, distributed storage

Fragmentation is routine storage behavior. Alternate data streams also support legitimate metadata and application workflows. Risk rises when an unusual named stream in a user-writable or execution-relevant location is created by an untrusted process and followed by decoding, copying, persistence, or execution.

Collect by file record and streamMFT recordattributes + runsUnnamed streamNamed streamExtent A · Extent C · Extent FHash · owner · execution context
The file record joins names and physical extents into one evidentiary object.

Detection and forensics

  • Inventory named streams in startup, profile, download, temporary, and web-content paths.
  • Correlate stream creation with process lineage, signer, network origin, and later reads.
  • Detect tools that copy only the unnamed stream and create acquisition blind spots.
  • Preserve MFT, USN, stream names, sizes, hashes, run lists, ACLs, and Zone metadata.

Use MFTECmd, Velociraptor, Plaso, and Volatility 3. A safe lab can place harmless text in a named stream and verify that inventory and acquisition retain it.

ATT&CK and controls

Alternate streams map to T1564.004 NTFS File Attributes; artifact breakup may overlap T1027. These are capabilities, not CVEs. Use stream-aware backup and collection, application control, endpoint monitoring, least privilege, and behavioral correlation rather than alerting on every stream.

← Previous: Attributes & LockingNext: PPID Spoofing →