Alternate Data Stream

Turkish equivalent: Alternatif veri akışıDomain: Digital Forensics

An NTFS feature that lets a file or directory hold additional named data streams beyond its primary unnamed content stream.

Digital-Forensics Context

NTFS alternate data streams let a file or directory hold named streams in addition to its primary unnamed data stream. Legitimate metadata such as zone information and intentionally concealed payloads can therefore exist outside the byte count users normally associate with the file.

Evidence Boundary

The presence of an ADS is not evidence of malicious activity by itself; Windows and applications use streams for legitimate purposes. Forensic interpretation requires stream enumeration, provenance, timestamps, and surrounding context.

Related technical publications

Publications whose title or summary directly references this concept.

C# Programming

Comprehensive C# 14 and .NET 10 notes covering the CLR, type system, OOP, generics, LINQ, async/await, threads, atomicity, channels, async streams, memory management, pipelines, I/O, networking, reflection, and production performance.

Spring Boot

Advanced Spring Boot notes for the Spring Boot 4 and Spring Framework 7 generation, covering auto-configuration, dependency injection, MVC/REST, Jakarta Persistence, transactions, security, testing, HTTP clients, virtual threads, observability, Native Image, and production reliability.

Operating Systems: Processes, Memory, Files and I/O

Operating-systems course notes covering processes, threads, CPU scheduling, concurrency, deadlock, virtual memory, files and I/O together with real-time scheduling, priority inversion, WCET, queues, and the modern I/O path.