LiveActive security incident?Get immediate response
MITRE ATT&CK® Technique

T1564.004: NTFS File Attributes

MITRE ATT&CK T1564.004: NTFS File Attributes Technique details for Windows, with detection guidance, relationships and mapped CVEs.

EnterpriseT1564.004Sub-techniqueObject v2.0Modified
Glexia's Take · Automated analysis

Security context for executives and security teams

Automation confidenceHigh

NTFS File Attributes matters because malicious content can be hidden in Windows file-system metadata such as Alternate Data Streams or Extended Attributes rather than appearing as normal files. For leaders, the risk is not the filesystem feature itself; it is the possibility that malware, tools, or payload data may sit outside the visibility of basic file inventory, static indicator scanning, or some antivirus workflows.

Executive priority

Prioritize this where Windows endpoints or servers are critical to operations, investigations, or compliance evidence. Ask whether security tooling can inspect NTFS metadata, not just visible filenames and hashes, and whether incident response playbooks include checks for hidden artifacts. This is especially relevant for resilience planning because multiple ATT&CK software entries are related to this technique, including ransomware and backdoor families, but local exposure depends on Windows asset coverage and telemetry quality.

Technical view

This is a Windows stealth sub-technique under Hide Artifacts. ATT&CK provides no official detection text, but the relationship to DET0432 indicates a detection strategy exists for NTFS file attribute abuse involving ADS/EAs. SOC and IR teams should validate whether endpoint tooling, forensic collection, and triage procedures can enumerate NTFS file attributes, identify suspicious data streams or extended attributes, and correlate them with process activity, file writes, and execution attempts. Because ADS/EAs can also have legitimate uses, detection should focus on unusual locations, unexpected creators, suspicious parent processes, and artifacts associated with known incident context rather than treating every stream as malicious.

Likely telemetry

  • Windows endpoint file-system telemetry covering file creation, modification, and metadata changes
  • NTFS-aware forensic artifacts, including Master File Table and file attribute inspection where available
  • Endpoint detection and response records for processes writing to or reading from unusual file attributes or streams
  • Command-line and process lineage telemetry associated with file manipulation utilities or suspicious execution chains
  • File integrity monitoring or host-based inventory data that can account for ADS/EAs, not only visible files

Detection direction

  • Validate coverage against DET0432 or an equivalent NTFS ADS/EA detection strategy in the local environment.
  • Confirm scanners and EDR tools inspect NTFS metadata and do not rely only on normal file paths, extensions, or hashes.
  • Tune detections to reduce noise from legitimate NTFS stream usage by considering path, signer, user context, parent process, and recent incident indicators.
  • During investigations, include NTFS attribute enumeration in host triage when malware is suspected but visible payload files are missing.
  • Use related ATT&CK context as prioritization input: this technique is linked to APT32 and multiple Windows malware/software entries, but do not infer current activity without local evidence.

Mitigation priorities

  • Apply least-privilege file and directory permissions as described by M1022, especially limiting unnecessary write access to sensitive directories and system locations.
  • Prioritize Windows endpoint hardening and monitoring on high-value systems where hidden artifacts would complicate recovery or evidence collection.
  • Ensure IR procedures and forensic tooling preserve and review NTFS attributes during collection and analysis.
  • Review whether vulnerability management and compliance evidence processes depend on file inventories that may miss ADS/EAs.
  • Use control validation exercises to confirm that hidden NTFS attribute content is discoverable by defensive tooling without relying on vendor assumptions.
Additional notes and limits

ATT&CK identifies this as T1564.004, a Windows sub-technique of Hide Artifacts. The supplied relationships show use by one group and multiple software entries, and a mitigation relationship to Restrict File and Directory Permissions. The most important defensive question is whether Windows file-system visibility includes NTFS metadata, because basic file scans may not be sufficient.

MITRE does not provide official detection guidance for this object in the supplied fields. This take is therefore based on the official description, external references, and stated relationships only. Actual detection feasibility, false positives, and risk priority require local endpoint tooling, Windows asset scope, and incident telemetry validation.

Generated from the cited source records. This long-tail analysis has not been individually reviewed by a named human.

Official MITRE ATT&CK definition

NTFS File Attributes

No official description is available in the imported ATT&CK source object.

View the same entry on attack.mitre.org (MITRE-hosted reference; in-page links above use the Glexia ATT&CK library.)

Glexia analysis

How security teams should use this page

Treat this object as behavior context, not an attribution claim. Validate the related groups, software, data sources, and mitigations against official ATT&CK relationships and your own telemetry before making control-coverage decisions.

ATT&CK relationship table

Related techniques

This mirrors the MITRE pattern of making group, software, campaign, and technique relationships scannable. Relationship notes come from mirrored ATT&CK relationship text when available.

2 rows
DomainIDNameRelationship / procedure
EnterpriseT1096NTFS File AttributesNTFS File Attributes revoked by this object.
EnterpriseT1564Hide ArtifactsThis object subtechnique of Hide Artifacts.
Associated objects

Groups, software, and campaigns

GroupEnterprise

G0050: APT32

APT32 is a suspected Vietnam-based threat group that has been active since at least 2014. The group has targeted multiple private sector industries as well as foreign governments, dissidents, and journalists with a strong focus on Southeast Asian countries like Vietnam, the Philippines, Laos, and Cambodia. They have extensively used strategic web compromises to compromise victims.[1][2][3]

MalwareEnterprise

S0019: Regin

Regin is a malware platform that has targeted victims in a range of industries, including telecom, government, and financial institutions. Some Regin timestamps date back to 2003. [1]

Windows
MalwareEnterprise

S0476: Valak

Valak is a multi-stage modular malware that can function as a standalone information stealer or downloader, first observed in 2019 targeting enterprises in the US and Germany.[1][2]

Windows
ToolEnterprise

S0361: Expand

Expand is a Windows utility used to expand one or more compressed CAB files.[1] It has been used by BBSRAT to decompress a CAB file into executable content.[2]

Windows
MalwareEnterprise

S0139: PowerDuke

PowerDuke is a backdoor that was used by APT29 in 2016. It has primarily been delivered through Microsoft Word or Excel attachments containing malicious macros. [1]

Windows
MalwareEnterprise

S1052: DEADEYE

DEADEYE is a malware launcher that has been used by APT41 since at least May 2021. DEADEYE has variants that can either embed a payload inside a compiled binary (DEADEYE.EMBED) or append it to the end of a file (DEADEYE.APPEND).[1]

Windows
MalwareEnterprise

S0145: POWERSOURCE

POWERSOURCE is a PowerShell backdoor that is a heavily obfuscated and modified version of the publicly available tool DNS_TXT_Pwnage. It was observed in February 2017 in spearphishing campaigns against personnel involved with United States Securities and Exchange Commission (SEC) filings at various organizations. The malware was delivered when macros were enabled by the victim and a VBS script was dropped. [1] [2]

Windows
MalwareEnterprise

S1160: Latrodectus

Latrodectus is a Windows malware downloader that has been used since at least 2023 to download and execute additional payloads and modules. Latrodectus has most often been distributed through email campaigns, primarily by TA577 and TA578, and has infrastructure overlaps with historic IcedID operations.[1][2][3]

Windows
MalwareEnterprise

S0570: BitPaymer

BitPaymer is a ransomware variant first observed in August 2017 targeting hospitals in the U.K. BitPaymer uses a unique encryption key, ransom note, and contact information for each operation. BitPaymer has several indicators suggesting overlap with the Dridex malware and is often delivered via Dridex.[1]

Windows
MalwareEnterprise

S0373: Astaroth

Astaroth is a Trojan and information stealer known to affect companies in Europe, Brazil, and throughout Latin America. It has been known publicly since at least late 2017. [1][2][3]

Windows
Relationship explorer

All related ATT&CK context

Mitigations

Mitigation direction

Change history

Object version and sync metadata

The fields below describe the current mirrored snapshot. When Glexia retains multiple ATT&CK source imports, you can open the table to compare the same object across releases (hashes and MITRE timestamps). For MITRE’s own release notes and roadmap, see ATT&CK resources — Updates.

ATT&CK release
19.1
Object version
2.0
Created
Modified
Raw hash
d157527b576bdb20...
Imported snapshots across ATT&CK releases(1)
ReleaseBundle importedObject versionModifiedStatusRaw hash
19.12.0Current bundled157527b576b…
Raw source

Mirrored ATT&CK source object

The raw object is retained through the mirrored ATT&CK source bundle and object hash. The raw endpoint returns the exact object from the mirrored bundle when available.

Source references

External references and citations

MITRE external references are preserved separately from Glexia analysis so citations remain traceable to their original source records.

  1. [1]
    SpectorOps Host-Based Jul 2017

    Atkinson, J. (2017, July 18). Host-based Threat Modeling & Indicator Design. Retrieved March 21, 2018.

    Open source URL
  2. [2]
    Microsoft NTFS File Attributes Aug 2010

    Hughes, J. (2010, August 25). NTFS File Attributes. Retrieved March 21, 2018.

    Open source URL
  3. [3]
    Microsoft File Streams

    Microsoft. (n.d.). File Streams. Retrieved September 12, 2024.

    Open source URL
  4. [4]
    MalwareBytes ADS July 2015

    Arntz, P. (2015, July 22). Introduction to Alternate Data Streams. Retrieved March 21, 2018.

    Open source URL
  5. [5]
    Microsoft ADS Mar 2014

    Marlin, J. (2013, March 24). Alternate Data Streams in NTFS. Retrieved March 21, 2018.

    Open source URL
  6. [6]
    Journey into IR ZeroAccess NTFS EA

    Harrell, C. (2012, December 11). Extracting ZeroAccess from NTFS Extended Attributes. Retrieved June 3, 2016.

  7. [7]
    Kaspersky Regin

    Kaspersky Lab's Global Research and Analysis Team. (2014, November 24). THE REGIN PLATFORM NATION-STATE OWNAGE OF GSM NETWORKS. Retrieved December 1, 2014.

    Open source URL
  8. [8]
    Cybereason Cobalt Kitty 2017

    Dahan, A. (2017). Operation Cobalt Kitty. Retrieved December 27, 2018.

    Open source URL
  9. [9]
    Cybereason Valak May 2020

    Salem, E. et al. (2020, May 28). VALAK: MORE THAN MEETS THE EYE . Retrieved June 19, 2020.

    Open source URL
  10. [10]
    Unit 42 Valak July 2020

    Duncan, B. (2020, July 24). Evolution of Valak, from Its Beginnings to Mass Distribution. Retrieved August 31, 2020.

    Open source URL
  11. [11]
    SentinelOne Valak June 2020

    Reaves, J. and Platt, J. (2020, June). Valak Malware and the Connection to Gozi Loader ConfCrew. Retrieved August 31, 2020.

    Open source URL
  12. [12]
    ESET LoJax Sept 2018

    ESET. (2018, September). LOJAX First UEFI rootkit found in the wild, courtesy of the Sednit group. Retrieved July 2, 2019.

    Open source URL
  13. [13]
    LOLBAS Esentutl

    LOLBAS. (n.d.). Esentutl.exe. Retrieved September 3, 2019.

    Open source URL
  14. [14]
    InsiderThreat NTFS EA Oct 2017

    Sander, J. (2017, October 12). Attack Step 3: Persistence with NTFS Extended Attributes – File System Attacks. Retrieved March 21, 2018.

    Open source URL
  15. [15]
    LOLBAS Expand

    LOLBAS. (n.d.). Expand.exe. Retrieved February 19, 2019.

    Open source URL
  16. [16]
    Volexity PowerDuke November 2016

    Adair, S.. (2016, November 9). PowerDuke: Widespread Post-Election Spear Phishing Campaigns Targeting Think Tanks and NGOs. Retrieved January 11, 2017.

    Open source URL
  17. [17]
    Mandiant APT41

    Rufus Brown, Van Ta, Douglas Bienstock, Geoff Ackerman, John Wolfram. (2022, March 8). Does This Look Infected? A Summary of APT41 Targeting U.S. State Governments. Retrieved July 8, 2022.

    Open source URL
  18. [18]
    Cisco DNSMessenger March 2017

    Brumaghin, E. and Grady, C.. (2017, March 2). Covert Channels and Poor Decisions: The Tale of DNSMessenger. Retrieved March 8, 2017.

  19. [19]
    Elastic Latrodectus May 2024

    Stepanic, D. and Bousseaden, S. (2024, May 15). Spring Cleaning with LATRODECTUS: A Potential Replacement for ICEDID. Retrieved September 13, 2024.

    Open source URL
  20. [20]
    Sentinel Labs WastedLocker July 2020

    Walter, J.. (2020, July 23). WastedLocker Ransomware: Abusing ADS and NTFS File Attributes. Retrieved September 14, 2021.

    Open source URL
  21. [21]
    Crowdstrike Indrik November 2018

    Frankoff, S., Hartley, B. (2018, November 14). Big Game Hunting: The Evolution of INDRIK SPIDER From Dridex Wire Fraud to BitPaymer Targeted Ransomware. Retrieved January 6, 2021.

    Open source URL
  22. [22]
    Securelist Brazilian Banking Malware July 2020

    GReAT. (2020, July 14). The Tetrade: Brazilian banking malware goes global. Retrieved November 9, 2020.

    Open source URL
  23. [23]
    ESET Gazer Aug 2017

    ESET. (2017, August). Gazing at Gazer: Turla’s new second stage backdoor. Retrieved September 14, 2017.

    Open source URL
  24. [24]
    Ciubotariu 2014

    Ciubotariu, M. (2014, January 23). Trojan.Zeroaccess.C Hidden in NTFS EA. Retrieved December 2, 2014.

  25. [25]
    Cyberreason Anchor December 2019

    Dahan, A. et al. (2019, December 11). DROPPING ANCHOR: FROM A TRICKBOT INFECTION TO THE DISCOVERY OF THE ANCHOR MALWARE. Retrieved September 10, 2020.

    Open source URL
  26. [26]
    Journey into IR ZeroAccess NTFS EA

    Harrell, C. (2012, December 11). Extracting ZeroAccess from NTFS Extended Attributes. Retrieved June 3, 2016.

  27. [27]
    Journey into IR ZeroAccess NTFS EA

    Harrell, C. (2012, December 11). Extracting ZeroAccess from NTFS Extended Attributes. Retrieved June 3, 2016.

  28. [28]
    MalwareBytes ADS July 2015

    Arntz, P. (2015, July 22). Introduction to Alternate Data Streams. Retrieved March 21, 2018.

    Open source URL
  29. [29]
    MalwareBytes ADS July 2015

    Arntz, P. (2015, July 22). Introduction to Alternate Data Streams. Retrieved March 21, 2018.

    Open source URL
  30. [30]
    Microsoft ADS Mar 2014

    Marlin, J. (2013, March 24). Alternate Data Streams in NTFS. Retrieved March 21, 2018.

    Open source URL
  31. [31]
    Microsoft ADS Mar 2014

    Marlin, J. (2013, March 24). Alternate Data Streams in NTFS. Retrieved March 21, 2018.

    Open source URL
  32. [32]
    Microsoft File Streams

    Microsoft. (n.d.). File Streams. Retrieved September 12, 2024.

    Open source URL
  33. [33]
    Microsoft File Streams

    Microsoft. (n.d.). File Streams. Retrieved September 12, 2024.

    Open source URL
  34. [34]
    Microsoft NTFS File Attributes Aug 2010

    Hughes, J. (2010, August 25). NTFS File Attributes. Retrieved March 21, 2018.

    Open source URL
  35. [35]
    Microsoft NTFS File Attributes Aug 2010

    Hughes, J. (2010, August 25). NTFS File Attributes. Retrieved March 21, 2018.

    Open source URL
  36. [36]
    SpectorOps Host-Based Jul 2017

    Atkinson, J. (2017, July 18). Host-based Threat Modeling & Indicator Design. Retrieved March 21, 2018.

    Open source URL
  37. [37]
    SpectorOps Host-Based Jul 2017

    Atkinson, J. (2017, July 18). Host-based Threat Modeling & Indicator Design. Retrieved March 21, 2018.

    Open source URL
  38. [38]
    mitre-attackT1564.004
    Open source URL
  39. [39]
    mitre-attackT1564.004
    Open source URL
  40. [40]
    mitre-attackT1564.004
    Open source URL
  41. [41]
    Kaspersky Regin

    Kaspersky Lab's Global Research and Analysis Team. (2014, November 24). THE REGIN PLATFORM NATION-STATE OWNAGE OF GSM NETWORKS. Retrieved December 1, 2014.

    Open source URL
  42. [42]
    Cybereason Cobalt Kitty 2017

    Dahan, A. (2017). Operation Cobalt Kitty. Retrieved December 27, 2018.

    Open source URL
  43. [43]
    Cybereason Valak May 2020

    Salem, E. et al. (2020, May 28). VALAK: MORE THAN MEETS THE EYE . Retrieved June 19, 2020.

    Open source URL
  44. [44]
    SentinelOne Valak June 2020

    Reaves, J. and Platt, J. (2020, June). Valak Malware and the Connection to Gozi Loader ConfCrew. Retrieved August 31, 2020.

    Open source URL
  45. [45]
    Unit 42 Valak July 2020

    Duncan, B. (2020, July 24). Evolution of Valak, from Its Beginnings to Mass Distribution. Retrieved August 31, 2020.

    Open source URL
  46. [46]
    ESET LoJax Sept 2018

    ESET. (2018, September). LOJAX First UEFI rootkit found in the wild, courtesy of the Sednit group. Retrieved July 2, 2019.

    Open source URL
  47. [47]
    LOLBAS Esentutl

    LOLBAS. (n.d.). Esentutl.exe. Retrieved September 3, 2019.

    Open source URL
  48. [48]
    InsiderThreat NTFS EA Oct 2017

    Sander, J. (2017, October 12). Attack Step 3: Persistence with NTFS Extended Attributes – File System Attacks. Retrieved March 21, 2018.

    Open source URL
  49. [49]
    LOLBAS Expand

    LOLBAS. (n.d.). Expand.exe. Retrieved February 19, 2019.

    Open source URL
  50. [50]
    Volexity PowerDuke November 2016

    Adair, S.. (2016, November 9). PowerDuke: Widespread Post-Election Spear Phishing Campaigns Targeting Think Tanks and NGOs. Retrieved January 11, 2017.

    Open source URL
  51. [51]
    Mandiant APT41

    Rufus Brown, Van Ta, Douglas Bienstock, Geoff Ackerman, John Wolfram. (2022, March 8). Does This Look Infected? A Summary of APT41 Targeting U.S. State Governments. Retrieved July 8, 2022.

    Open source URL
  52. [52]
    Cisco DNSMessenger March 2017

    Brumaghin, E. and Grady, C.. (2017, March 2). Covert Channels and Poor Decisions: The Tale of DNSMessenger. Retrieved March 8, 2017.

  53. [53]
    Elastic Latrodectus May 2024

    Stepanic, D. and Bousseaden, S. (2024, May 15). Spring Cleaning with LATRODECTUS: A Potential Replacement for ICEDID. Retrieved September 13, 2024.

    Open source URL
  54. [54]
    Sentinel Labs WastedLocker July 2020

    Walter, J.. (2020, July 23). WastedLocker Ransomware: Abusing ADS and NTFS File Attributes. Retrieved September 14, 2021.

    Open source URL
  55. [55]
    Crowdstrike Indrik November 2018

    Frankoff, S., Hartley, B. (2018, November 14). Big Game Hunting: The Evolution of INDRIK SPIDER From Dridex Wire Fraud to BitPaymer Targeted Ransomware. Retrieved January 6, 2021.

    Open source URL
  56. [56]
    Securelist Brazilian Banking Malware July 2020

    GReAT. (2020, July 14). The Tetrade: Brazilian banking malware goes global. Retrieved November 9, 2020.

    Open source URL
  57. [57]
    ESET Gazer Aug 2017

    ESET. (2017, August). Gazing at Gazer: Turla’s new second stage backdoor. Retrieved September 14, 2017.

    Open source URL
Source and licensing

Source: MITRE ATT&CK®. © 2026 The MITRE Corporation. This work is reproduced and distributed with the permission of The MITRE Corporation. MITRE ATT&CK and ATT&CK are registered trademarks of The MITRE Corporation. Glexia is not affiliated with or endorsed by MITRE.