Hide Navigation Hide TOC Run PowerShell Script from ADS (45a594aa-1fbd-4972-a809-ff5a99dd81b8) Detects PowerShell script execution from Alternate Data Stream (ADS) Cluster A Galaxy A Cluster B Galaxy B Level NTFS File Attributes - T1564.004 (f2857333-11d4-45bf-b064-2c28d8525be5) Attack Pattern Run PowerShell Script from ADS (45a594aa-1fbd-4972-a809-ff5a99dd81b8) Sigma-Rules 1 NTFS File Attributes - T1564.004 (f2857333-11d4-45bf-b064-2c28d8525be5) Attack Pattern Hide Artifacts - T1564 (22905430-4901-4c2a-84f6-98243cb173f8) Attack Pattern 2