What is an NTFS alternate data stream, and how does Windows use one to mark files downloaded from the internet?
answer
- a file is several named streams
- colon syntax after the filename
- dir shows the default stream's size only
- the download mark lives in a stream
- non-NTFS copy drops it
basics
~20 sNTFS stores a file as a set of named data streams, not one blob. Content beyond the default unnamed stream is an alternate data stream, addressed as file.txt:name. Windows writes one called Zone.Identifier to record that a file came from the internet.
solid answer
~50 sOn NTFS a file is a container of named streams. The bytes you normally see live in the default unnamed stream; any additional named stream is an *alternate data stream*, written and read as `filename:streamname`. Streams share the file's security descriptor and timestamps, and the size `dir` reports is the default stream only — so an alternate stream consumes disk space that ordinary listings hide. The best-known use is mark-of-the-web: when a browser or mail client saves a download, it writes a small `Zone.Identifier` stream containing `[ZoneTransfer]` and `ZoneId=3`, meaning the internet zone. Office Protected View, SmartScreen and script-host warnings all key off that stream. It is why a downloaded file behaves differently from a locally created one, and why the mark vanishes when you copy the file to FAT32 or exFAT, which have no concept of streams.
code
powershell · 3 linesGet-Item -Path .\setup.exe -Stream *
Get-Content -Path .\setup.exe -Stream Zone.Identifier
Unblock-File -Path .\setup.exego deeper
Know that an NTFS file can hold extra named data beyond its visible content, that it is written as filename:streamname, and that downloads carry such a marker which is why Windows warns about them.
Explain that content lives in named $DATA attributes, that the default stream is what tools report a size for, and that the download marker is an INI fragment with a ZoneId value.
Reason about the consequences in production: audit and backup tooling that copies only the primary stream loses the mark, non-NTFS hops strip it silently, and hidden stream data can inflate real disk usage invisibly.
Weigh whether your organisation depends on mark-of-the-web as a control at all, given how easily an archive round-trip or a USB copy erases it, and decide what layer actually enforces untrusted-content policy.
## A file is a set of streams Most people picture a file as one sequence of bytes plus metadata. NTFS does not work that way. Internally an NTFS file is a record in the Master File Table holding a set of *attributes*, and file content is stored in `$DATA` attributes — plural. The unnamed `$DATA` attribute is the content every tool shows you. Any additional `$DATA` attribute has a name, and that is an alternate data stream (ADS). The naming syntax exposed to userland is `path:streamname`, with a fully explicit form of `path:streamname:$DATA`. The default stream can be written explicitly as `file.txt::$DATA`. Streams are addressable by the normal file APIs, so anything that can open a path can open a stream: ``` echo hidden > notes.txt:secret more < notes.txt:secret dir /R ``` Properties worth knowing: - Streams belong to the file, so they share one security descriptor, one set of timestamps and one hard-link identity. You cannot ACL a stream separately from its file. - They consume real allocation, but `dir` and Explorer's size column report the default stream. A 1 KB file can be sitting on megabytes of stream data. - Directories can carry streams too. - They are an NTFS feature (also present on ReFS in a limited form); FAT32 and exFAT have no equivalent. ## Mark-of-the-web The feature most engineers actually meet is the `Zone.Identifier` stream. When Edge, Chrome, Outlook or a modern archive tool writes a file that came from outside the machine, it attaches a stream whose content is an INI fragment: ``` [ZoneTransfer] ZoneId=3 HostUrl=https://example.com/setup.exe ``` `ZoneId` maps to the old Internet Explorer security zones: 0 local machine, 1 local intranet, 2 trusted sites, 3 internet, 4 restricted sites. Anything at 3 or above is treated as untrusted content. A surprising amount of Windows security UX hangs off that one stream. Office opens the document in Protected View instead of enabling macros. SmartScreen evaluates the executable before running it. The script hosts and some installers warn. Right-clicking the file and ticking **Unblock** — or running PowerShell's `Unblock-File` — simply deletes the stream, after which the file behaves like anything you authored locally. This is also the mechanism behind a class of "it works on my machine" support tickets: a colleague emails a ZIP, the recipient extracts it with a tool that propagates the mark to every extracted file, and suddenly a build script or DLL is treated as untrusted. ## Why streams silently disappear Because the mark is metadata that only NTFS can store, it is lost whenever the file crosses a boundary that cannot carry streams: - copying to FAT32 or exFAT (a USB stick, an SD card); - most archive formats — a plain ZIP stores the default stream only, which is why zipping and unzipping is a folk remedy for "unblocking" a whole folder; - transfers over protocols and tools that copy only the primary stream. The inverse is the security worry: because streams are hidden from casual listings, they have been used to stash payloads. `dir /R` in cmd, and `Get-Item -Stream *` in PowerShell, are how you look. Modern endpoint tooling inspects streams, so this is more of a forensics topic than a live evasion technique — but an interviewer asking about ADS is usually probing whether you know files can carry content that `dir` does not show. ## What to say in an interview Lead with the model: NTFS files are multi-stream, the alternate stream is addressed with a colon, it shares the file's ACL and timestamps, and it is invisible to size-based tooling. Then give the one use everybody has actually hit — `Zone.Identifier` and the downloaded-file warnings — and close with the practical consequence that copying through a non-NTFS filesystem or a ZIP silently strips it. That sequence shows you understand the mechanism rather than having read a list of NTFS features.
- Do alternate data streams have their own permissions?No. Streams are attributes of one file object, so they share the file's security descriptor, owner and timestamps. If a principal can open the file, it can open its streams; you cannot grant access to the default stream while denying an alternate one.
- Why does zipping and unzipping a folder often clear the downloaded-file warnings?The warning comes from the `Zone.Identifier` stream, and a plain ZIP stores only each file's default stream. Round-tripping through the archive discards the mark. Note the opposite also happens: some extraction tools deliberately propagate the mark from the archive to every extracted file.
- What is the ZoneId value that means the file came from the internet?`ZoneId=3`. The values follow the old Internet Explorer zones — 0 local machine, 1 local intranet, 2 trusted sites, 3 internet, 4 restricted sites — and anything at 3 or above is treated as untrusted by SmartScreen, Protected View and similar checks.
saying these in an interview costs you the question
- Thinks a file has exactly one data stream
- Assumes dir's size column includes alternate streams
- Believes a stream can be ACL'd separately from its file
- Says the download mark is stored in the registry
- Claims streams survive a copy to a FAT32 drive