ATTRIB
Windows Attribute Command: Display and modify file attributes.
ATTRIBUTES#
R Read-only # Cannot modify/delete H Hidden # Hidden from normal view S System # System file A Archive # Modified since backup I Not Content Indexed # Exclude from indexing L Symbolic Link # (Display only) O Offline # (Display only) X No scrub # Exclude from integrity
BASIC USAGE#
attrib file.txt # Show attributes attrib *.txt # Show for multiple files attrib C:\folder\* # All files in folder attrib /s # Subdirectories attrib /d # Process directories too
SET ATTRIBUTES#
attrib +r file.txt # Set read-only attrib +h file.txt # Set hidden attrib +s file.txt # Set system attrib +a file.txt # Set archive attrib +i file.txt # Set not indexed
MULTIPLE ATTRIBUTES#
attrib +r +h file.txt # Read-only and hidden attrib +r +h +s file.txt # Read-only, hidden, system
REMOVE ATTRIBUTES#
attrib -r file.txt # Remove read-only attrib -h file.txt # Remove hidden attrib -s file.txt # Remove system attrib -a file.txt # Remove archive attrib -r -h -s file.txt # Remove multiple
RECURSIVE OPERATIONS#
attrib +h folder\* /s # Hide all files in folder attrib -h folder\* /s # Unhide all files attrib +h folder\* /s /d # Include directories attrib -r -h -s folder\* /s /d # Remove all from everything
VIEW HIDDEN FILES#
attrib /s /d # Show all files with attributes attrib *.* /s # All files in current dir tree # Find hidden files attrib /s | findstr /i "H" # Files with H attribute attrib /s /d | findstr /i "SH" # System + Hidden
COMMON OPERATIONS#
HIDE FILE#
attrib +h secret.txt
HIDE AND PROTECT#
attrib +h +s +r file.txt # Hard to find/modify
UNHIDE EVERYTHING#
attrib -h -s -r *.* /s /d
MAKE FILE READ-ONLY#
attrib +r important.doc
PROTECT FOLDER#
attrib +h +s folder # Hide folder attrib +h +s folder\* /s /d # Hide contents
RECOVER HIDDEN FILES#
# After virus hides files attrib -h -s -r *.* /s /d
MALWARE REMOVAL#
# Malware often uses +h +s to hide # Remove from all drives attrib -h -s -r C:\*.* /s /d attrib -h -s -r D:\*.* /s /d # Common malware locations attrib -h -s -r "%TEMP%\*" /s /d attrib -h -s -r "%APPDATA%\*" /s /d
SECURITY ANALYSIS#
# Find suspiciously hidden files attrib /s /d C:\Users\* | findstr /i "SHR" attrib /s /d C:\Windows\Temp\* | findstr /i "H" # Check startup folders attrib "%APPDATA%\Microsoft\Windows\Start Menu\Programs\Startup\*"
USB DRIVE CLEANUP#
# Remove hidden attribute from all USB files attrib -h -s -r E:\*.* /s /d
ALTERNATE DATA STREAMS#
# Attrib doesn't handle ADS # Use dir /r or streams.exe (Sysinternals)
WITH WILDCARDS#
attrib +h *.log # Hide all log files attrib +r *.docx # Protect all Word docs attrib -h *.* /s # Unhide all files recursively
QUICK REFERENCE#
# View attrib file.txt # View attributes attrib /s /d # View all (recursive) # Set attrib +r file.txt # Read-only attrib +h file.txt # Hidden attrib +s file.txt # System attrib +a file.txt # Archive # Remove attrib -r file.txt # Remove read-only attrib -h file.txt # Remove hidden attrib -s file.txt # Remove system attrib -r -h -s file.txt # Remove all # Recursive attrib +h folder\* /s # Files in subdirs attrib +h folder\* /s /d # Files and directories # Common combinations attrib +h +s +r file.txt # Maximum protection attrib -h -s -r *.* /s /d # Unhide everything
NOTES#
# H + S combination is "super hidden" # Requires unchecking "Hide protected OS files" to see # System Restore points use this protection # Some attributes require admin: # - Setting S (System) on files # - Modifying files in system directories
ATTRIB CHEATSHEET ================= Source: https://cheatsheet.johlem.net Windows Attribute Command: Display and modify file attributes. ATTRIBUTES ========== R Read-only # Cannot modify/delete H Hidden # Hidden from normal view S System # System file A Archive # Modified since backup I Not Content Indexed # Exclude from indexing L Symbolic Link # (Display only) O Offline # (Display only) X No scrub # Exclude from integrity BASIC USAGE =========== attrib file.txt # Show attributes attrib *.txt # Show for multiple files attrib C:\folder\* # All files in folder attrib /s # Subdirectories attrib /d # Process directories too SET ATTRIBUTES ============== attrib +r file.txt # Set read-only attrib +h file.txt # Set hidden attrib +s file.txt # Set system attrib +a file.txt # Set archive attrib +i file.txt # Set not indexed MULTIPLE ATTRIBUTES ------------------- attrib +r +h file.txt # Read-only and hidden attrib +r +h +s file.txt # Read-only, hidden, system REMOVE ATTRIBUTES ================= attrib -r file.txt # Remove read-only attrib -h file.txt # Remove hidden attrib -s file.txt # Remove system attrib -a file.txt # Remove archive attrib -r -h -s file.txt # Remove multiple RECURSIVE OPERATIONS ==================== attrib +h folder\* /s # Hide all files in folder attrib -h folder\* /s # Unhide all files attrib +h folder\* /s /d # Include directories attrib -r -h -s folder\* /s /d # Remove all from everything VIEW HIDDEN FILES ================= attrib /s /d # Show all files with attributes attrib *.* /s # All files in current dir tree # Find hidden files attrib /s | findstr /i "H" # Files with H attribute attrib /s /d | findstr /i "SH" # System + Hidden COMMON OPERATIONS ================= HIDE FILE --------- attrib +h secret.txt HIDE AND PROTECT ---------------- attrib +h +s +r file.txt # Hard to find/modify UNHIDE EVERYTHING ----------------- attrib -h -s -r *.* /s /d MAKE FILE READ-ONLY ------------------- attrib +r important.doc PROTECT FOLDER -------------- attrib +h +s folder # Hide folder attrib +h +s folder\* /s /d # Hide contents RECOVER HIDDEN FILES -------------------- # After virus hides files attrib -h -s -r *.* /s /d MALWARE REMOVAL =============== # Malware often uses +h +s to hide # Remove from all drives attrib -h -s -r C:\*.* /s /d attrib -h -s -r D:\*.* /s /d # Common malware locations attrib -h -s -r "%TEMP%\*" /s /d attrib -h -s -r "%APPDATA%\*" /s /d SECURITY ANALYSIS ================= # Find suspiciously hidden files attrib /s /d C:\Users\* | findstr /i "SHR" attrib /s /d C:\Windows\Temp\* | findstr /i "H" # Check startup folders attrib "%APPDATA%\Microsoft\Windows\Start Menu\Programs\Startup\*" USB DRIVE CLEANUP ================= # Remove hidden attribute from all USB files attrib -h -s -r E:\*.* /s /d ALTERNATE DATA STREAMS ====================== # Attrib doesn't handle ADS # Use dir /r or streams.exe (Sysinternals) WITH WILDCARDS ============== attrib +h *.log # Hide all log files attrib +r *.docx # Protect all Word docs attrib -h *.* /s # Unhide all files recursively QUICK REFERENCE --------------- # View attrib file.txt # View attributes attrib /s /d # View all (recursive) # Set attrib +r file.txt # Read-only attrib +h file.txt # Hidden attrib +s file.txt # System attrib +a file.txt # Archive # Remove attrib -r file.txt # Remove read-only attrib -h file.txt # Remove hidden attrib -s file.txt # Remove system attrib -r -h -s file.txt # Remove all # Recursive attrib +h folder\* /s # Files in subdirs attrib +h folder\* /s /d # Files and directories # Common combinations attrib +h +s +r file.txt # Maximum protection attrib -h -s -r *.* /s /d # Unhide everything NOTES ----- # H + S combination is "super hidden" # Requires unchecking "Hide protected OS files" to see # System Restore points use this protection # Some attributes require admin: # - Setting S (System) on files # - Modifying files in system directories
Defensive reference on CyberRamen. Offensive / red-team sheets live on OffensiveRamen.com.