Hexacorn Ltd - Good Alternate Data Streams (ADS)
"While ADS is not widely supported/used by many apps (maybe with the exception of malware
), it can be still used for some interesting purposes. In this short article, I describe a few legitimate uses of ADS by Windows that I know of.
If you know some others or if you spot any mistake, please let me know. Thanks.
This post is loosely based on the Microsoft list, but it contains some more details and looks at these streams from a ‘forensic angle’.
Related Past Post XRef:   
ADSdotNET – Access NTFS Alternate Data Streams from your managed languages without P/Invoke    
Accessing NTFS Alternate Data Streams with C#    
HijackThis gets all open. Download the VB6 (yes, VB6) code now...
I'm not sure if you've heard this, but the Windows 8 "ReFS" does not support named streams: http://blogs.msdn.com/b/b8/archive/2012/01/16/building-the-next-generation-file-system-for-windows-refs.aspx
ReplyDeleteYep, sure did...
ReplyDeleteBut ReFS is for Windows 8 Server. It's not part of Windows 8 Client at this point and it's going to be a while before it makes that jump (heck in ReFS v1 you can't even boot off it).
But great point, ADS's days might be numbered (assuming ReFS takes off, that ADS isn't added back, yada, yada...)