Skip to content

$Secure:$SDS

Evidence: $Secure:$SDS
Description: Dump Contents of $Secure:$SDS
Category: DiskFilesystem
Platform: windows
Short Name: securesds
Is Parsed: No
Sent to Investigation Hub: Yes
Collect File(s): Yes

The $Secure file contains security descriptors for all files and directories on the NTFS volume. These descriptors include access control lists (ACLs), ownership information, and audit settings. The $SDS alternate data stream stores the actual security descriptor data, which is referenced by file entries to avoid duplication.

This collector gathers structured data about $secure:$sds.

FieldDescriptionExample
TypeFile typeSecureSDS
NameFile name$Secure:$SDS
SourcePathOriginal pathC:$Secure:$SDS
FilePathPath in evidenceNTFSFiles/$Secure_$SDS
FileSizeFile size in bytes10485760

This collector uses kernel driver NTFS raw access to read $Secure:$SDS from each fixed NTFS drive.

Security descriptors provide critical information about file permissions, ownership, and access control. This data can reveal unauthorized access, privilege escalation attempts, and security policy violations. Essential for investigating insider threats and understanding who had access to sensitive files.