A relatively unknown compatibility feature of NTFS, Alternate Data Streams (ADS) provides hackers with a method of hiding root kits or hacker tools on a breached system and allows them to be executed without being detected by the systems administrator. adsalternatedatantfsrootkitstreams with alternatedatastreamsthreat
by Don Parker 1. Introduction The purpose of this article is to explain the existence of alternate data streams in Microsoft Windows, demonstrate how to create them by compromising a machine using the Metasploit Framework, and then use freeware tools to easily discover these hidden files. antivirusendpointprotectionsecurityfocussymantec with alternatedatantfsstreamswindows