daemon-sec-cheatsheet

The cheatsheet vault for operators: AD, enumeration, exploitation, priv-esc, web, DFIR
git clone https://git.daemon-sec.xyz/daemon-sec-cheatsheet.git
Log | Files | Refs | README | LICENSE

commit 3088740f8029d4c6d0d4eb49a8b0b1f76e2506dc
parent 073ee579d4cb0d1d5292b748731dd999663bfd3c
Author: DAEMON <zer0sec.xp@icloud.com>
Date:   Thu, 17 Sep 2026 01:38:08 +0100

Expand ADS enumeration; make the potato→ADS link explicit

alternate-data-streams-guide.md: 'Finding streams' -> 'Finding & enumerating
streams', adding dir /s /r (recursive, with a findstr filter to drop the
noise of every file's own unnamed ::$DATA stream), a cleaner filtered/
formatted PowerShell recursive sweep, streams64.exe, and a comparison table
of all four methods (recursive?, needs what, best for).

potato-attacks-guide.md: the SYSTEM payload cookbook now explicitly calls
out ADS as one of the things SYSTEM gets you (staging AND finding data
other users hid), not just a footnote callout.

Diffstat:
Msrc/content/sheets/pentest-workflow/alternate-data-streams-guide.md | 63++++++++++++++++++++++++++++++++++++++++++++++++++++-----------
Msrc/content/sheets/pentest-workflow/potato-attacks-guide.md | 9++++++---
2 files changed, 58 insertions(+), 14 deletions(-)

diff --git a/src/content/sheets/pentest-workflow/alternate-data-streams-guide.md b/src/content/sheets/pentest-workflow/alternate-data-streams-guide.md @@ -41,9 +41,11 @@ Why it matters to both sides of the keyboard: --- -## Finding streams — the part that matters most `fas:MagnifyingGlass` +## Finding & enumerating streams `fas:MagnifyingGlass` -This is the question that actually comes up on an engagement or a box: *does this file have anything hidden on it?* Plain `dir` and Explorer will never tell you — you have to ask specifically. +This is the question that actually comes up on an engagement or a box: *does this file — or this whole directory tree — have anything hidden on it?* Plain `dir` and Explorer will never tell you. Four ways to ask, from the always-available one-liner up to a full-drive sweep. + +### `dir /r` — one directory, no tooling required ```batch :: cmd — /r reveals streams next to each file (look for the "file:stream:$DATA" lines) @@ -59,24 +61,63 @@ A tell-tale stream line looks like this — a file whose visible content is tiny That second line is the whole discovery: `hm.txt` has a named stream called `root.txt`. Nothing about the plain `36 hm.txt` line hints at it. +### `dir /s /r` — the same thing, recursively + +Add `/s` to walk every subdirectory instead of checking one folder at a time — the reflex to use once you land somewhere and want to sweep the whole profile or drive in one shot: + +```batch +:: Every file, every subfolder, streams and all — a whole profile in one command +dir /s /r C:\Users\Administrator + +:: Narrow the noise: only lines that mention a stream +dir /s /r C:\Users\Administrator | findstr /R /C:":.*\$DATA$" | findstr /V /C:"::\$DATA" +``` + +The `findstr` filter matters at scale: every file has its own unnamed `::$DATA` stream, and `dir /r` prints that for **every single file** — the second `findstr /V` drops those so only genuinely *named* streams (the interesting ones) survive. + +> [!warning]+ `dir /s /r` is loud and can be slow on a big tree +> `fas:TriangleExclamation` +> Recursing an entire user profile or `C:\` is fine on a CTF box; on a real engagement it's a lot of filesystem I/O and (without the `findstr` filter above) a wall of output that buries the one line you care about. Scope it to the directories that matter — profile roots, web roots, `Temp` — rather than reflexively pointing it at `C:\`. + +### PowerShell — cleanest output, easiest to filter + ```powershell -# PowerShell — list every stream on one file +# One file Get-Item C:\Windows\Temp\notes.txt -Stream * -# Hunt an entire tree for anything carrying a non-default stream -Get-ChildItem C:\Users -Recurse -ErrorAction SilentlyContinue | ForEach-Object { - Get-Item $_.FullName -Stream * -ErrorAction SilentlyContinue -} | Where-Object Stream -ne ':$DATA' +# A whole tree, filtered to only files that actually carry an extra stream — +# prints exactly the file + stream name, nothing else +Get-ChildItem C:\Users -Recurse -File -ErrorAction SilentlyContinue | ForEach-Object { + Get-Item -LiteralPath $_.FullName -Stream * -ErrorAction SilentlyContinue +} | Where-Object Stream -ne ':$DATA' | Select-Object FileName, Stream, Length ``` +The `Select-Object` at the end is the difference between a readable table (`FileName`, `Stream`, `Length`) and a wall of default property dumps — worth keeping when you're sweeping anything bigger than a single directory. + +### Sysinternals `streams.exe` — purpose-built, no scripting needed + ```batch -:: Sysinternals streams.exe — purpose-built, recursive, works from cmd with no PowerShell -streams.exe -s C:\Users +:: Recursive sweep, quiet banner +streams.exe -nobanner -s C:\Users + +:: A single file +streams.exe -nobanner C:\Windows\Temp\notes.txt ``` -> [!tip]+ Which one to reach for +`streams64.exe` is the same tool for 64-bit targets if the plain binary won't run. Not bundled here — grab it from [Microsoft's Sysinternals downloads](https://learn.microsoft.com/sysinternals/downloads/streams) (or land it via SMB/`certutil` per the [Potato Attacks guide's delivery section](/sheets/pentest-workflow/potato-attacks-guide#delivery--getting-a-potato-onto-the-box-and-running-it-fasrocketlaunch) — the same transport tricks apply to any tool, not just potatoes). + +### Which one to reach for + +| Method | Recursive? | Needs | Best for | +|---|---|---|---| +| `dir /r` | No (one directory) | Nothing — always available | Quick check on a directory you're already looking at | +| `dir /s /r` (+ `findstr` filter) | Yes | Nothing — always available | Sweeping a whole profile/tree from cmd with no extra tooling, non-interactive shells | +| PowerShell `Get-Item`/`Get-ChildItem -Stream` | Optional (both shown above) | PowerShell | Cleanest, filterable, scriptable output — the one to reach for when you're already in a PS session | +| `streams.exe` / `streams64.exe` | Yes (`-s`) | The binary itself (not built in) | Purpose-built recursive sweep when you'd rather not write a PowerShell one-liner, or from cmd on a box you don't want to touch with PowerShell | + +> [!tip]+ In a non-interactive shell (a potato firing one command and exiting) > `fas:Lightbulb` -> `dir /r` is the reflex — it's always available, no PowerShell or extra tooling needed, and works from a one-shot non-interactive command just as well as an interactive shell. Reach for the PowerShell recursive hunt or `streams.exe` when you want to sweep an entire profile or drive at once instead of checking directory-by-directory. +> All four work the same way as anything else non-interactive: redirect to a file you can read back. `dir /s /r C:\Users\Administrator > ads.txt 2>&1` then `type ads.txt` — exactly the pattern used throughout the [Potato Attacks guide's field method](/sheets/pentest-workflow/potato-attacks-guide#4--fire-it-non-interactively-and-actually-read-the-output-fasterminal). --- diff --git a/src/content/sheets/pentest-workflow/potato-attacks-guide.md b/src/content/sheets/pentest-workflow/potato-attacks-guide.md @@ -400,13 +400,16 @@ What to actually run once a potato lands you SYSTEM. Track every artefact you cr :: Stage a Meterpreter/Sliver/C2 beacon as SYSTEM ... "cmd /c C:\Windows\Temp\beacon.exe" + +:: Hide/find data with NTFS Alternate Data Streams — see the ADS guide, linked below +... "cmd /c dir /r C:\Users\Administrator\Desktop" ``` Then pull the hives and crack offline: `impacket-secretsdump -sam sam.sav -system sys.sav LOCAL`. -> [!info]+ Staging the binary itself without it showing in a directory listing +> [!info]+ SYSTEM is also your ticket into Alternate Data Streams > `fas:Lightbulb` -> Drop the potato binary inside an NTFS Alternate Data Stream on a boring file (`type g.exe > log.txt:g.exe`) so a casual `dir` in `C:\Windows\Temp` shows nothing, then extract it back to a normal path right before you run it. Full mechanics — reading, writing, hiding, and stripping Mark-of-the-Web — are in the [Alternate Data Streams guide](/sheets/pentest-workflow/alternate-data-streams-guide). +> Two uses, both worth knowing: **stage** the potato binary itself inside an ADS on a boring file (`type g.exe > log.txt:g.exe`) so a casual `dir` in `C:\Windows\Temp` shows nothing, then extract it back out right before you run it; and **find** data other users hid the same way — SYSTEM can now `dir /r` every profile on the box, and flags/creds/second-stage tooling turn up there more often than you'd expect. Full mechanics — reading, writing, finding, hiding, and stripping Mark-of-the-Web — are in the **[Alternate Data Streams guide](/sheets/pentest-workflow/alternate-data-streams-guide)**. --- @@ -595,7 +598,7 @@ Remove-Item C:\Windows\Temp\sam.sav, C:\Windows\Temp\sys.sav -Force -ErrorAction net user backdoor /del 2>$null # if you created one ``` -Staged a payload inside an ADS as part of this chain? The [Alternate Data Streams guide's cleanup section](/sheets/pentest-workflow/alternate-data-streams-guide#detection-opsec--cleanup) covers removing streams. +Staged a payload inside an ADS as part of this chain? The [Alternate Data Streams guide's cleanup section](/sheets/pentest-workflow/alternate-data-streams-guide#detection-opsec--cleanup-fasshield) covers removing streams. ---