.. /Tar.exe
Star

Alternate data streams (Compression)
Copy (Compression)

Used by Windows to extract and create archives.


Paths:

Resources:
Acknowledgements:

Detection:

Alternate data streams

  1. Compress one or more files to an alternate data stream (ADS).

    tar -cf compressedfilename:ads C:\folder\file
    Use case
    Can be used to evade defensive countermeasures, or to hide as part of a persistence mechanism
    Privileges required
    User
    Operating systems
    Windows 10, Windows 11
    ATT&CK® technique
    T1564.004
    Tags
    Type: Compression
    This LOLBAS involves (de)compression of one or more files.
  2. Decompress a compressed file from an alternate data stream (ADS).

    tar -xf compressedfilename:ads
    Use case
    Can be used to evade defensive countermeasures, or to hide as part of a persistence mechanism
    Privileges required
    User
    Operating systems
    Windows 10, Windows 11
    ATT&CK® technique
    T1564.004
    Tags
    Type: Compression
    This LOLBAS involves (de)compression of one or more files.

Copy

  1. Extracts archive.tar from the remote (internal) host (host1) to the current host.

    tar -xf \\host1\archive.tar
    Use case
    Copy files
    Privileges required
    User
    Operating systems
    Windows 10, Windows 11
    ATT&CK® technique
    T1105
    Tags
    Type: Compression
    This LOLBAS involves (de)compression of one or more files.