# GhostTree Attack Abuses Windows Junctions to Hide Malware From EDR and Security Tools
Researchers have discovered a novel file system evasion technique that exploits a fundamental feature of Windows NTFS to help attackers hide malicious files from endpoint detection and response (EDR) systems and antivirus tools. The attack, dubbed GhostTree, leverages NTFS junctions—a built-in file system feature designed for legitimate purposes—to create recursive directory loops that cause security scanners to either crash, timeout, or skip the malicious payload entirely.
The technique is particularly dangerous because it requires no elevated privileges and can be executed by any user with basic write permissions. Unlike advanced exploitation methods that target zero-day vulnerabilities, GhostTree works against the architecture of Windows file systems themselves, making it a fundamental challenge that security teams must address immediately.
## The Threat: A Deceptively Simple Evasion Method
GhostTree is not a new malware variant or a complex attack framework. Instead, it's a file system manipulation technique that turns a legitimate Windows feature into a weapon against defenders. By creating recursive junctions—directory pointers that loop back to parent directories—attackers can generate an effectively infinite number of valid file paths pointing to the same malicious executable.
Security tools tasked with recursively scanning directory structures can fall into these loops, becoming trapped in an endless traversal that never reaches the malicious files hidden within. Modern EDR solutions and antivirus software, which rely on deep directory scanning and enumeration, may:
What makes this technique particularly insidious is its simplicity and its exploitation of a fundamental design decision in Windows—one that has existed for decades and is unlikely to be patched away without breaking backward compatibility.
## Background and Context: NTFS Junctions Explained
To understand GhostTree, it's essential to understand how Windows junctions work and why they exist.
NTFS (New Technology File System) introduced several advanced features beyond simple file hierarchies. Two of the most powerful are:
1. Junctions – NTFS reparse points that redirect one directory to another transparently
2. Symbolic links – Similar to junctions but with broader capabilities
These features were designed to solve legitimate problems:
Creating a junction requires only a single command and ordinary user permissions:
mklink /J C:\LinkToFolder C:\TargetFolderNo administrator privileges are needed. No audit trail is logged by default. Any user with write access to a directory can create a junction pointing anywhere on the system.
## Technical Details: From GhostBranch to GhostTree
Researchers identified two related techniques, each more sophisticated than the last.
### GhostBranch: The Simple Loop
The simpler variant, GhostBranch, creates a single recursive loop by pointing a child directory back to its parent:
C:\Parent\program.exe (original file)
mklink /J C:\Parent\Child C:\Parent (create junction)This creates a logical loop where C:\Parent\Child now contains everything the parent does, including itself. The result is an unlimited number of valid paths to the same file:
C:\Parent\program.exeC:\Parent\Child\program.exeC:\Parent\Child\Child\program.exeC:\Parent\Child\Child\Child\program.exeA security tool scanning recursively will keep following the loop infinitely, never reaching the end.
### GhostTree: The Branching Attack
GhostTree escalates the concept by creating *multiple* junctions that all loop back to the parent:
mklink /J C:\Parent\Child1 C:\Parent
mklink /J C:\Parent\Child2 C:\ParentNow each level in the path has multiple branching options. A recursive scanner doesn't just follow one infinite loop—it faces exponential path combinations:
C:\Parent\Child1\program.exeC:\Parent\Child2\program.exeC:\Parent\Child1\Child1\program.exeC:\Parent\Child1\Child2\program.exeC:\Parent\Child2\Child1\program.exeWith just two junction points, a scanner attempting to enumerate all paths faces 2^n possible combinations at depth *n*. This causes:
There is one practical limit: Windows enforces a maximum path length of 260 characters by default (extendable to 32,767 via registry, but most tools don't support it). This limits how deep the recursive loops can go but still allows enough branching to defeat most scanners.
## How It Evades Detection: Why EDR Tools Struggle
Modern endpoint detection and response platforms rely on several detection methods:
| Detection Method | GhostTree Impact |
|---|---|
| File enumeration scans | Infinite loops cause timeouts |
| Recursive directory crawling | Exponential path combinations overwhelm the tool |
| Hash-based detection | File exists but is never reached during enumeration |
| Behavioral monitoring | May still detect execution, but not the hidden staging |
| Real-time file access monitoring | Works if triggered at execution time |
The weakness is that many EDR tools perform *batch scans* during off-hours or deployment phases. These scheduled scans are vulnerable to timeout or resource exhaustion. Additionally, some tools may use cached directory listings that fail to update when new junctions are created.
## Implications for Organizations
GhostTree exposes a fundamental gap in how security tools interact with the Windows file system:
### 1. Detection Blind Spot
Malware staged in junction-based directory structures may evade initial detection, giving attackers a window to move laterally or establish persistence before EDR tools catch the execution.
### 2. Staged Attack Scenarios
Attackers could use GhostTree to hide:
### 3. Privilege Escalation Staging
Since any user can create junctions, an attacker with user-level access could stage privilege escalation exploits in hidden directory structures, then execute them when the timing is right.
### 4. Supply Chain Implications
Third-party software deployed with write permissions to system directories could be trojanized by attackers using this technique, hiding malicious components from post-deployment scanning.
## Recommendations: Immediate and Long-Term Actions
### Immediate Actions (This Week)
1. Update EDR Configuration
- Test your EDR tool's handling of recursive junctions
- Enable path depth limits if available
- Configure timeouts to fail safely (alert on timeout, don't skip)
- Check vendor patches or hotfixes
2. Audit Existing Junctions
Run a one-time audit to identify suspicious junctions:
```
fsutil reparsepoint query C:\ /s
```
Establish a baseline of legitimate junctions (many Windows systems have few or none).
3. Restrict Junction Creation
Use Group Policy to limit who can create junctions:
- Policy: Computer Configuration > Windows Settings > Security Settings > File System
- Target: Restrict to service accounts and administrators only
- Audit: Enable auditing for junction creation attempts
### Medium-Term (This Month)
4. Behavioral Detection
- Monitor for mklink /J command execution
- Alert on recursive directory structures with loops
- Track file execution from unusual path depths
- Correlate junction creation with subsequent file modifications
5. Vendor Engagement
- Contact your EDR vendor for GhostTree-specific detection
- Request information on path traversal handling
- Ask about recursive loop detection capabilities
### Long-Term Strategy (This Quarter)
6. File System Hardening
- Disable junctions entirely where not required (via registry)
- Implement mandatory junction logging at the file system level
- Use SACL (System Access Control Lists) to audit junction creation
7. Process-Level Monitoring
- Monitor what processes access which files
- Use guaranteed file access logging to catch execution even if directory scans fail
- Implement guaranteed file auditing on sensitive directories
8. Threat Hunting
- Hunt for junctions in unusual locations (temp directories, user profiles, staging areas)
- Look for patterns of rapid junction creation followed by file execution
- Correlate with suspicious process execution
---
## HackWire Analysis
Why GhostTree matters now: This attack highlights a critical blind spot in how modern security tools interact with Windows file systems. While EDR solutions have become sophisticated at detecting malware behaviors, process execution, and network communications, they remain vulnerable to simple file system tricks that exploit design constraints rather than software bugs. The fact that this technique requires no privileges and no exploits makes it immediately accessible to any attacker with basic system access—and difficult to defend against without architectural changes to how scanners work.
Pattern recognition: GhostTree is part of a broader trend of *fileless* and *filesystem-based* evasion techniques. We've seen attackers abuse alternate data streams, hard links, and now junctions. Each technique exploits a legitimate Windows feature that defenders overlook because they're designed for compatibility, not security. The common thread: Windows maintains backward compatibility with legacy features, and attackers exploit that tension.
Hidden risk: The biggest danger is timing. An attacker could stage a multi-stage payload using GhostTree, hide it from EDR for weeks, and only execute it when a specific condition is met—a particular user logs in, an application launches, a scheduled task runs. By then, the staging files have aged past typical retention periods, and the attack appears to "just happen" with no obvious preparation.
Concrete next steps: Organizations should prioritize three things: (1) run fsutil to baseline existing junctions—if you find any you don't recognize, treat them as indicators of compromise; (2) test your EDR against synthetic GhostTree structures before attackers do it for real; and (3) contact your security vendor today about guidance, not next quarter. The longer you wait, the higher the probability someone in your network is already testing this.
— HackWire Editorial
---
## Related Coverage