NTFS Alternate Data Stream (ADS) Abuse - T1564.004

Detects the creation, reading, or execution of payloads stored within NTFS Alternate Data Streams (ADS). This technique is commonly used by adversaries to hide malicious content within file metadata to evade security tools. The rule monitors process command-line arguments for ADS syntax, identifies usage of utilities like type, Get-Content, wmic, or various LOLBins (e.g., regsvr32, rundll32) interacting with ADS paths, and flags anomalous file creation/modification events that involve ADS, excluding known system-generated streams.