title: NTFS Vulnerability Exploitation id: f14719ce-d3ab-4e25-9ce6-2899092260b0 description: This the exploitation of a NTFS vulnerability as reported without many details via Twitter status: experimental author: Florian Roth date: 2021/01/11 modified: 2021/11/17 references: - https://twitter.com/jonasLyk/status/1347900440000811010 - https://twitter.com/wdormann/status/1347958161609809921 - https://www.bleepingcomputer.com/news/security/windows-10-bug-corrupts-your-hard-drive-on-seeing-this-files-icon/ logsource: product: windows service: system detection: selection: Provider_Name: Ntfs EventID: 55 Origin: 'File System Driver' Description|contains|all: - 'contains a corrupted file record' - 'The name of the file is "\"' condition: selection falsepositives: - Unlikely level: high tags: - attack.impact - attack.t1499.001