T1096: Alternate Data Streams
Execution
echo "this is benign" > benign.txt
Get-ChildItem



Observations


References
Last updated
echo "this is benign" > benign.txt
Get-ChildItem





Last updated
cmd '/c echo "this is evil" > benign.txt:evil.txt'notepad .\benign.txt:evil.txtGet-Item c:\experiment\evil.txt -Stream *
Get-Content .\benign.txt -Stream evil.txt