Keylogger Data Stored in an ADS, (Tue, Jul 15th) SANS Internet Storm Center, InfoCON: green
If many malware samples try to be "filess" (read: they try to reduce their filesystem footprint to the bare minimum), another technique remains interesting: Alternate Data Streams or "ADS"[1]. This …