NTFS Alternate Data Stream (ADS) Execution Abuse - T1564.004
Detects the use of NTFS Alternate Data Streams (ADS) by monitoring process command lines, initiating process command lines, and folder paths for patterns indicative of ADS notation. The rule specifically flags potential execution or access patterns involving common script interpreters (wscript, cscript, powershell, pwsh) combined with ADS, as well as general ADS usage in file paths.
Microsoft Sentinel (KQL)

