Talk With an Expert

Hunting Payloads in Linux Extended File Attributes

Hunting Payloads in Linux Extended File Attributes (PDF, 1.34MB)Last updated: 28 Sep, 2025
Presented by:
Xavier Mertens
Xavier Mertens

Linux Extended File Attributes provide functionality similar to NTFS Alternate Data Streams (ADS). While often used for legitimate purposes, they can also be abused to conceal malicious content. Attackers may hide payloads, encrypted data, or other artifacts within these attributes —making detection and forensic analysis more challenging. This session will demonstrate both sides of the equation: How adversaries can hide a simple payload in extended attributes and how defenders can detect and investigate such misuse. Gain practical insights into the offensive and defensive techniques surrounding Linux extended attributes, to help you strengthen your hunting and incident response capabilities.

SANS DFIR Europe Prague 2025