A stream is a sequence of bytes. NTFS stores files as collections of attributes inside Master File Table (MFT) records.

MFT Records

A typical file record looks like this:

MFT record for hm.txt
├── $STANDARD_INFORMATION
├── $FILE_NAME
├── unnamed $DATA
└── named $DATA called "secret"

Stream Sizes

Each stream has:

  • The allocation size is the amount of disk space that is reserved for a stream.
  • The actual size is the number of bytes that are being used by a caller.
  • The valid data length (VDL) is the number of bytes that are initialized from the allocation size for the stream.

Stream Names

The full name of a stream is _filename_:_stream name_:_stream type . Users can only use existing stream types. The default data stream is unnamed.

Stream Types

Stream TypeDescription
::$ATTRIBUTE_LISTContains a list of all attributes that make up the file and identifies where each attribute is located.
::$BITMAPA bitmap used by indexes to manage the b-tree free space for a directory. The b-tree is managed in 4 KB chunks (regardless of cluster size) and this is used to manage the allocation of these chunks. This stream type is present on every directory.
::$DATAData stream. The default data stream has no name. Data streams can be enumerated using the FindFirstStreamW and FindNextStreamW functions.
::$EAContains Extended Attributes data.
::$EA_INFORMATIONContains support information about the Extended Attributes.
::$FILE_NAMEThe name of the file, in Unicode characters. This includes the short name of the file as well as any hard links.
::$INDEX_ALLOCATIONThe stream type of a directory. Used to implement filename allocation for large directories. This stream represents the directory itself and contains all of the data of the directory. Changes to streams of this type are logged to the NTFS change journal. The default stream name of an I30 so “DirName”, “DirName::I30:$INDEX_ALLOCATION” are all equivalent.
::$INDEX_ROOTThis stream represents root of the b-tree of an index. This stream type is present on every directory.
::$LOGGED_UTILITY_STREAMSimilar to ::StreamType” pair for EFS is “:LOGGED_UTILITY_STREAM” and for TxF is “:LOGGED_UTILITY_STREAM”.
::$OBJECT_IDAn 16-byte ID used to identify the file for the link-tracking service.
::$REPARSE_POINTThe reparse point data.

List Alternate Streams

# display alternate streams on Windows
cmd /c "dir /r"