Antinel

← All 24 rules

DST-09 Alternate data stream write (file path)

block 0 hits here sandbox-verified

① What it stops

Agent attempted to write an NTFS alternate data stream (path:stream) -- invisible to dir/ls and carried along by a plain file copy

Stored in the file's own stream table, an ADS does not show up in normal listings or in the copy that gets reviewed. Write the bytes as a normal file instead.

② Criteria

ItemValue
Severitycritical
Categorydestructive
GateGate 4 behavior (destructive/persistence)
Criterion typetool_call
Applies toWrite、Edit

File path patterns

Generated directly from rules/default.json — never hand-written or paraphrased.

③ Real hits

2026-09-24T01:44:27+08:00 ✗ block [DST-09] tool: Write exit code: 2 criterion: path hit: .txt:

Triggered in a disposable sandbox project using the real hooks/pre_tool_use.py — the same method as challenge/generate_challenge.py. All 24 rules verified this way (24/24).

Zero hits in the 13-day ledger on this machine — we do not post a sample. Zero hits means this machine never hit it, not that the rule is dead; effectiveness is covered by the sandbox trigger above.

④ False positives & exemptions

Built-in exclude patterns are listed under ②. Four exemption mechanisms exist globally (declared workspace roots, policy path whitelist, path-suspect alert-only, exclude patterns); counts on this machine are published on the Chinese page and in Limits.

⑤ Boundaries

Boundary
Criterion typetool_call
Applies toWrite、Edit
Platformnt
Case sensitivityMeasured: insensitive (RM -RF is blocked like rm -rf)
Path normalisationMeasured: effective (./sub/../.env is blocked)
Scripts not parsedAn absolute path outside the project mentioned in a Bash command is alerted, not blockedscripts are not parsed (THREAT_MODEL Non-goals)
Failure posturefail-open; best-effort, not a hard security boundary

⑥ Reproduce

grep -h "DST-09" .psl/audit/*.jsonl | head python challenge/generate_challenge.py python challenge/verify.py
Cite this page

Antinel AgentState. DST-09 Alternate data stream write (file path) — rule detail. https://antinel.com/en/agentstate/rules/DST-09/ (accessed YYYY-MM-DD)

Antinel. (2026). DST-09 Alternate data stream write (file path) — rule detail. AgentState. https://antinel.com/en/agentstate/rules/DST-09/

BibTeX

@misc{antinel_en_agentstate_rules_DST_09,
  title        = {DST-09 Alternate data stream write (file path) — rule detail},
  author       = {{Antinel}},
  year         = {2026},
  url          = {https://antinel.com/en/agentstate/rules/DST-09/},
  note         = {claim tier: measured}
}

Claim tier: measured 采集时刻:2026-09-23T22:41:18+08:00