commit 3088740f8029d4c6d0d4eb49a8b0b1f76e2506dc
parent 073ee579d4cb0d1d5292b748731dd999663bfd3c
Author: DAEMON <zer0sec.xp@icloud.com>
Date: Thu, 17 Sep 2026 01:38:08 +0100
Expand ADS enumeration; make the potato→ADS link explicit
alternate-data-streams-guide.md: 'Finding streams' -> 'Finding & enumerating
streams', adding dir /s /r (recursive, with a findstr filter to drop the
noise of every file's own unnamed ::$DATA stream), a cleaner filtered/
formatted PowerShell recursive sweep, streams64.exe, and a comparison table
of all four methods (recursive?, needs what, best for).
potato-attacks-guide.md: the SYSTEM payload cookbook now explicitly calls
out ADS as one of the things SYSTEM gets you (staging AND finding data
other users hid), not just a footnote callout.
Diffstat:
2 files changed, 58 insertions(+), 14 deletions(-)
diff --git a/src/content/sheets/pentest-workflow/alternate-data-streams-guide.md b/src/content/sheets/pentest-workflow/alternate-data-streams-guide.md
@@ -41,9 +41,11 @@ Why it matters to both sides of the keyboard:
---
-## Finding streams — the part that matters most `fas:MagnifyingGlass`
+## Finding & enumerating streams `fas:MagnifyingGlass`
-This is the question that actually comes up on an engagement or a box: *does this file have anything hidden on it?* Plain `dir` and Explorer will never tell you — you have to ask specifically.
+This is the question that actually comes up on an engagement or a box: *does this file — or this whole directory tree — have anything hidden on it?* Plain `dir` and Explorer will never tell you. Four ways to ask, from the always-available one-liner up to a full-drive sweep.
+
+### `dir /r` — one directory, no tooling required
```batch
:: cmd — /r reveals streams next to each file (look for the "file:stream:$DATA" lines)
@@ -59,24 +61,63 @@ A tell-tale stream line looks like this — a file whose visible content is tiny
That second line is the whole discovery: `hm.txt` has a named stream called `root.txt`. Nothing about the plain `36 hm.txt` line hints at it.
+### `dir /s /r` — the same thing, recursively
+
+Add `/s` to walk every subdirectory instead of checking one folder at a time — the reflex to use once you land somewhere and want to sweep the whole profile or drive in one shot:
+
+```batch
+:: Every file, every subfolder, streams and all — a whole profile in one command
+dir /s /r C:\Users\Administrator
+
+:: Narrow the noise: only lines that mention a stream
+dir /s /r C:\Users\Administrator | findstr /R /C:":.*\$DATA$" | findstr /V /C:"::\$DATA"
+```
+
+The `findstr` filter matters at scale: every file has its own unnamed `::$DATA` stream, and `dir /r` prints that for **every single file** — the second `findstr /V` drops those so only genuinely *named* streams (the interesting ones) survive.
+
+> [!warning]+ `dir /s /r` is loud and can be slow on a big tree
+> `fas:TriangleExclamation`
+> Recursing an entire user profile or `C:\` is fine on a CTF box; on a real engagement it's a lot of filesystem I/O and (without the `findstr` filter above) a wall of output that buries the one line you care about. Scope it to the directories that matter — profile roots, web roots, `Temp` — rather than reflexively pointing it at `C:\`.
+
+### PowerShell — cleanest output, easiest to filter
+
```powershell
-# PowerShell — list every stream on one file
+# One file
Get-Item C:\Windows\Temp\notes.txt -Stream *
-# Hunt an entire tree for anything carrying a non-default stream
-Get-ChildItem C:\Users -Recurse -ErrorAction SilentlyContinue | ForEach-Object {
- Get-Item $_.FullName -Stream * -ErrorAction SilentlyContinue
-} | Where-Object Stream -ne ':$DATA'
+# A whole tree, filtered to only files that actually carry an extra stream —
+# prints exactly the file + stream name, nothing else
+Get-ChildItem C:\Users -Recurse -File -ErrorAction SilentlyContinue | ForEach-Object {
+ Get-Item -LiteralPath $_.FullName -Stream * -ErrorAction SilentlyContinue
+} | Where-Object Stream -ne ':$DATA' | Select-Object FileName, Stream, Length
```
+The `Select-Object` at the end is the difference between a readable table (`FileName`, `Stream`, `Length`) and a wall of default property dumps — worth keeping when you're sweeping anything bigger than a single directory.
+
+### Sysinternals `streams.exe` — purpose-built, no scripting needed
+
```batch
-:: Sysinternals streams.exe — purpose-built, recursive, works from cmd with no PowerShell
-streams.exe -s C:\Users
+:: Recursive sweep, quiet banner
+streams.exe -nobanner -s C:\Users
+
+:: A single file
+streams.exe -nobanner C:\Windows\Temp\notes.txt
```
-> [!tip]+ Which one to reach for
+`streams64.exe` is the same tool for 64-bit targets if the plain binary won't run. Not bundled here — grab it from [Microsoft's Sysinternals downloads](https://learn.microsoft.com/sysinternals/downloads/streams) (or land it via SMB/`certutil` per the [Potato Attacks guide's delivery section](/sheets/pentest-workflow/potato-attacks-guide#delivery--getting-a-potato-onto-the-box-and-running-it-fasrocketlaunch) — the same transport tricks apply to any tool, not just potatoes).
+
+### Which one to reach for
+
+| Method | Recursive? | Needs | Best for |
+|---|---|---|---|
+| `dir /r` | No (one directory) | Nothing — always available | Quick check on a directory you're already looking at |
+| `dir /s /r` (+ `findstr` filter) | Yes | Nothing — always available | Sweeping a whole profile/tree from cmd with no extra tooling, non-interactive shells |
+| PowerShell `Get-Item`/`Get-ChildItem -Stream` | Optional (both shown above) | PowerShell | Cleanest, filterable, scriptable output — the one to reach for when you're already in a PS session |
+| `streams.exe` / `streams64.exe` | Yes (`-s`) | The binary itself (not built in) | Purpose-built recursive sweep when you'd rather not write a PowerShell one-liner, or from cmd on a box you don't want to touch with PowerShell |
+
+> [!tip]+ In a non-interactive shell (a potato firing one command and exiting)
> `fas:Lightbulb`
-> `dir /r` is the reflex — it's always available, no PowerShell or extra tooling needed, and works from a one-shot non-interactive command just as well as an interactive shell. Reach for the PowerShell recursive hunt or `streams.exe` when you want to sweep an entire profile or drive at once instead of checking directory-by-directory.
+> All four work the same way as anything else non-interactive: redirect to a file you can read back. `dir /s /r C:\Users\Administrator > ads.txt 2>&1` then `type ads.txt` — exactly the pattern used throughout the [Potato Attacks guide's field method](/sheets/pentest-workflow/potato-attacks-guide#4--fire-it-non-interactively-and-actually-read-the-output-fasterminal).
---
diff --git a/src/content/sheets/pentest-workflow/potato-attacks-guide.md b/src/content/sheets/pentest-workflow/potato-attacks-guide.md
@@ -400,13 +400,16 @@ What to actually run once a potato lands you SYSTEM. Track every artefact you cr
:: Stage a Meterpreter/Sliver/C2 beacon as SYSTEM
... "cmd /c C:\Windows\Temp\beacon.exe"
+
+:: Hide/find data with NTFS Alternate Data Streams — see the ADS guide, linked below
+... "cmd /c dir /r C:\Users\Administrator\Desktop"
```
Then pull the hives and crack offline: `impacket-secretsdump -sam sam.sav -system sys.sav LOCAL`.
-> [!info]+ Staging the binary itself without it showing in a directory listing
+> [!info]+ SYSTEM is also your ticket into Alternate Data Streams
> `fas:Lightbulb`
-> Drop the potato binary inside an NTFS Alternate Data Stream on a boring file (`type g.exe > log.txt:g.exe`) so a casual `dir` in `C:\Windows\Temp` shows nothing, then extract it back to a normal path right before you run it. Full mechanics — reading, writing, hiding, and stripping Mark-of-the-Web — are in the [Alternate Data Streams guide](/sheets/pentest-workflow/alternate-data-streams-guide).
+> Two uses, both worth knowing: **stage** the potato binary itself inside an ADS on a boring file (`type g.exe > log.txt:g.exe`) so a casual `dir` in `C:\Windows\Temp` shows nothing, then extract it back out right before you run it; and **find** data other users hid the same way — SYSTEM can now `dir /r` every profile on the box, and flags/creds/second-stage tooling turn up there more often than you'd expect. Full mechanics — reading, writing, finding, hiding, and stripping Mark-of-the-Web — are in the **[Alternate Data Streams guide](/sheets/pentest-workflow/alternate-data-streams-guide)**.
---
@@ -595,7 +598,7 @@ Remove-Item C:\Windows\Temp\sam.sav, C:\Windows\Temp\sys.sav -Force -ErrorAction
net user backdoor /del 2>$null # if you created one
```
-Staged a payload inside an ADS as part of this chain? The [Alternate Data Streams guide's cleanup section](/sheets/pentest-workflow/alternate-data-streams-guide#detection-opsec--cleanup) covers removing streams.
+Staged a payload inside an ADS as part of this chain? The [Alternate Data Streams guide's cleanup section](/sheets/pentest-workflow/alternate-data-streams-guide#detection-opsec--cleanup-fasshield) covers removing streams.
---