Alternate Data Stre...
 
Notifications
Clear all

Alternate Data Streams related cases

9 Posts
7 Users
0 Reactions
571 Views
(@forenz)
Eminent Member
Joined: 18 years ago
Posts: 47
Topic starter  

Hi, i'm writing a paper on ADSes and was wondering if anyone could point me to documentation that contains details of cases that have involved these in the past - malware, stolen documents for example.

Any help here would be great, if you think of anything that is related to ADSes and you think might be relevant could you also let me know please.

Your help is appreciated, thanks.


   
Quote
keydet89
(@keydet89)
Famed Member
Joined: 21 years ago
Posts: 3568
 

"Windows Forensic Analysis" contains some of what you're looking for. Unfortunately, in most instances, the specific details of an examination or case are not made available to that level.

I'm sure that spending some time on Google would turn up some interesting information, as well.


   
ReplyQuote
(@forenz)
Eminent Member
Joined: 18 years ago
Posts: 47
Topic starter  

I have "Windows Forensic Analysis" haha, i've already used that as a help. Thats what i thought but i also thought people on here might know better and also - why exactly can ADSes not be viewed in Windows XP? is the answer as simple as there being no native tools or is there a more in depth one? if there is i'd like to know.

Thanks for the reply


   
ReplyQuote
keydet89
(@keydet89)
Famed Member
Joined: 21 years ago
Posts: 3568
 

So, on pg 242 of WFA, the book states that there are no native tools (caveat this applies to Windows NT, 2000, XP and 2003…fig 5.11 on pg 244 illustrates how to do this on Vista) in Windows that allow you to view arbitrary ADSs.

If you can find a native tool on Windows NT through 2003 that can be used to locate and view arbitrary ADSs, please…I'm sure we'd all love to hear about it.


   
ReplyQuote
(@ronanmagee)
Estimable Member
Joined: 20 years ago
Posts: 145
 

Theres a good article with an example of how it might be used … here

The LADS tool should also help you.

I believe ADS was first introduced to allow windows to be compatible with Macs.

Sysinternals tool called stream may also help.

Ronan


   
ReplyQuote
darren_q
(@darren_q)
Eminent Member
Joined: 20 years ago
Posts: 48
 

ADSspy - http//www.bleepingcomputer.com/files/adsspy.php - is another good one


   
ReplyQuote
ecophobia
(@ecophobia)
Estimable Member
Joined: 17 years ago
Posts: 127
 

I still have this page bookmarked http//www2.tech.purdue.edu/cit/Courses/cit556/readings/NTFSDarkside.pdf

One guy by the name H. Carvey did an excellent write up about ADS. The paper is quite old, so must be the guy who wrote the paper.
) Hello Harlan -)

SANS aalso got something about ADS.
http//sansforensics.wordpress.com/2009/02/09/the-trojan-solved-it-catching-a-fraudster-with-another-criminal-myspacceexe/


   
ReplyQuote
(@ivalen)
Eminent Member
Joined: 18 years ago
Posts: 30
 

Hi, i'm writing a paper on ADSes and was wondering if anyone could point me to documentation that contains details of cases that have involved these in the past - malware, stolen documents for example.

Not going to reveal case specifics, but one malware case I worked involved the collection of data prior to archiving and exfiltration by using ADS. Each file to be exfiltrated was copied as an ADS to a single folder, those streams RAR'd, and the RAR transmitted out.


   
ReplyQuote
 rohn
(@rohn)
New Member
Joined: 18 years ago
Posts: 1
 

Although for the most part they don't answer your specific question, hear are links to some articles I've collected. Maybe you will find something useful in them or in the links they contain

Dissecting NTFS Hidden Streams

FAQ Alternate Data Streams in NTFS

Windows Security Threat -- NTFS Alternate Data Streams

Practical Guide to Alternative Data Streams in NTFS

Hidden Threat Alternate Data Streams

The Dark Side of NTFS (Microsoft’s Scarlet Letter)

Alternate Data Streams- Big Deal or Not?

Zone Identifier ADS's

Alternate Data Streams - What's hiding in your windows NTFS

HTH


   
ReplyQuote
Share: