Threat reportThreat IntelligenceTL-2026-0821
GhostTree / GhostBranch: Recursive NTFS Directory Junctions Abused to Evade Recursive File Scanners and Hide Malware
GhostTree / GhostBranch (TL-2026-0821), also tracked as GhostTree, is a medium-severity tracked intrusion set, first published 2026-06-16. It has no confirmed attribution, affects Microsoft Microsoft Defender Antivirus (Windows Defender) recursive, maps to 14 MITRE ATT&CK techniques (T1027, T1036, T1036.005), and is covered by 9 detection rules and 18 indicators of compromise.
- Severity
- MEDIUMAssessed severity
- CVEs
- 0None referenced
- Techniques
- 14MITRE ATT&CK
- Actors
- 0Not attributed
- Detection rules
- 9SPL · KQL · Sigma
- IOCs
- 18Indicators of compromise
Key facts for TL-2026-0821
- Threat ID
- TL-2026-0821
- Also known as
- GhostTree, GhostBranch
- Severity
- MEDIUM
- Status
- PATCHED
- Category
- THREAT_INTEL
- First published
- Last reviewed
- Attribution confidence
- NONE
- Motivation
- UNKNOWN
- Detection rules
- 9
- Indicators of compromise
- 18
How GhostTree / GhostBranch works
GhostTree (and its single-junction variant GhostBranch) abuses legitimate Windows NTFS directory junctions to manufacture an astronomically large number of valid file paths that all resolve to the same location, causing recursive directory scanners — including Windows Defender and EDR products — to loop, hang, or skip files and leave co-located malware unscanned. The technique requires only standard-user write permissions (mklink /J). Microsoft initially closed the report as 'not crossing a security boundary' before patching the underlying recursive-scan behavior.
GhostTree is a Windows defense-evasion technique disclosed by Varonis Threat Labs (researcher Dolev Taler) on 2026-06-16. It weaponizes NTFS directory junctions — reparse points (IO_REPARSE_TAG_MOUNT_POINT) that transparently redirect directory access — to create self-referential, recursive directory loops on disk.
The simpler variant, GhostBranch, uses a single junction that points a child directory back at its own parent: `mklink /J C:\Parent\Child C:\Parent`. Because the junction resolves to its ancestor, the file system exposes an endless ladder of valid paths to the same file: C:\Parent\Child\Program.exe, C:\Parent\Child\Child\Program.exe, and so on. Any tool that walks the directory tree recursively will keep descending into the loop and never terminate.
GhostTree amplifies this by creating multiple child junctions at each level that each point back to the parent (e.g. `mklink /J C:\Parent\Child1 C:\Parent` and `mklink /J C:\Parent\Child2 C:\Parent`), producing a branching tree. Varonis calculates that with binary branching constrained by Windows' path-length limits the structure yields roughly 2^126 ≈ 8.5 × 10^37 distinct valid paths to a single executable — vastly more than the estimated number of grains of sand on Earth (~8.5 × 10^18).
Windows enforces a traditional maximum path length (MAX_PATH) of 260 characters, which caps recursion at approximately 126 nested directory levels when single-character folder names are used. This limit can be raised to 32,767 characters via the LongPathsEnabled registry value, though many applications and utilities still cannot handle paths beyond 260, so attackers can use the legacy limit while still defeating scanners.
The security impact is on recursive directory traversal. Varonis tested the technique against Windows Defender (Microsoft Defender Antivirus) and confirmed it could evade folder scans: the scanning engine becomes consumed following the directory loop and ultimately hangs without completing, so malware placed alongside the junctions remains unscanned and undetected by the endpoint agent. The same failure mode affects EDR products that perform unbounded recursive directory scans. This behaves as a denial-of-service against the security scanner itself, providing cover for arbitrary co-located payloads.
The technique is notable because it requires only standard write permissions rather than administrative privileges — any low-privileged user (or a foothold process) can create junctions with the built-in mklink utility or the CreateSymbolicLink / DeviceIoControl(FSCTL_SET_REPARSE_POINT) APIs. Varonis reported the issue to Microsoft, who initially closed the ticket with the explanation that 'bypassing Defender is not crossing a security boundary,' but Microsoft subsequently patched the recursive-scanning behavior regardless.
No CVE was assigned. No in-the-wild exploitation, malware family, threat-actor attribution, or network indicators (C2 IPs, domains, or file hashes) were reported in the source material; consequently there is no network infrastructure to correlate (BeaconBeagle pivot is not applicable). The indicators below are behavioral/host-based artifacts of the technique itself. Defenders are advised to monitor file-system activity at the data layer — anomalous junction/reparse-point creation and recursive directory structures that should not exist under normal operation — rather than relying solely on recursive native scanning, and to apply current Microsoft Defender platform updates.
MITRE ATT&CK techniques used in TL-2026-0821
Defense Evasion
T1027 Obfuscated Files or Information; T1036 Masquerading; T1036.005 Match Legitimate Resource Name or Location; T1070 Indicator Removal; T1070.004 File Deletion; T1564 Hide Artifacts; T1564.004 NTFS File Attributes
Execution
T1059 Command and Scripting Interpreter; T1059.001 PowerShell; T1059.003 Windows Command Shell; T1106 Native API
defense-impairment
T1112 Modify Registry; T1685 Disable or Modify Tools
Impact
Affected products and versions in GhostTree / GhostBranch
- Microsoft — Microsoft Defender Antivirus (Windows Defender) recursive directory scanning
Vulnerable versions: Recursive-scan engine prior to fix (specific build undisclosed)
Fixed in: Patched Defender platform/engine update (date undisclosed) - Microsoft — Windows NTFS directory junctions / reparse points
Vulnerable versions: Junction creation available to standard users on supported Windows versions - Multiple — EDR / antivirus products performing unbounded recursive directory traversal
Vulnerable versions: Implementations without reparse-loop / depth handling
Remediation for GhostTree / GhostBranch
Patches
- Microsoft patched the underlying recursive directory-scanning behavior in Microsoft Defender Antivirus (specific KB/build and date not disclosed in public reporting).
Immediate actions
- Apply current Microsoft Defender Antivirus platform/engine updates, which include the fix for the recursive directory-scanning behavior abused by GhostTree/GhostBranch.
- Hunt for self-referential NTFS directory junctions whose reparse target resolves to an ancestor of the link itself (recursive loops).
Workarounds
- Detect and remove malicious junctions with fsutil reparsepoint query / fsutil reparsepoint delete or PowerShell reparse-point inspection.
- Restrict or alert on junction creation in sensitive directories; treat single-character nested directory chains as suspicious.
Longer-term hardening
- Monitor file-system activity at the data layer (e.g. minifilter/audit telemetry) to detect anomalous junction/reparse-point creation and recursive directory structures, rather than relying solely on recursive native file scanners.
- Adopt defense-in-depth so that a single recursive-scan evasion does not leave endpoints blind; correlate process creation (mklink/cmd.exe) with reparse-point creation events.
- Configure scanners/EDR with traversal depth limits, loop/cycle detection, and reparse-point handling so directory walks terminate safely.
Weaknesses (CWE) in GhostTree / GhostBranch
Timeline of GhostTree / GhostBranch
- Varonis recommended data-layer file-system monitoring for anomalous junction/reparse-point creation and recursive directory structures rather than relying solely on recursive native scanning.
- No CVE was assigned and no in-the-wild exploitation, malware family, or threat-actor attribution was reported; the disclosure is a defensive PoC against recursive directory scanners.
- Researchers noted the recursion depth can be extended beyond the 260-character MAX_PATH limit to 32,767 characters by enabling the LongPathsEnabled registry value.
- Varonis documented two variants: GhostBranch (single self-referential junction yielding ~126 nested path levels) and GhostTree (multi-junction branching yielding ~2^126 ≈ 8.5 × 10^37 distinct paths to one file).
- Technique covered by BleepingComputer, Cyber Security News, GBHackers, and CyberPress.
- Microsoft subsequently patched the underlying recursive directory-scanning behavior despite the initial triage decision (specific KB/build/date undisclosed).
- Researchers reported the issue to Microsoft; the ticket was initially closed with the explanation that 'bypassing Defender is not crossing a security boundary.'
- Varonis validated the technique against Windows Defender, confirming recursive folder scans hang and leave co-located files unscanned.
- Varonis Threat Labs (researcher Dolev Taler) publicly disclosed the GhostTree / GhostBranch NTFS-junction evasion technique.
Sources cited for GhostTree / GhostBranch
- GhostTree: Unveiling Path Manipulation Techniques to Bypass Windows Security (Varonis Threat Labs)
- GhostTree attack abused recursive Windows junctions to hide malware (BleepingComputer)
- New GhostTree Attack Causing EDR Products to Hang and Leave Files Unscanned (Cyber Security News)
- New GhostTree Attack Causes EDR Tools to Hang, Leaving Files Unscanned (GBHackers)
- GhostTree Attack Causes EDR Tools to Hang, Skip File Scans (CyberPress)
- MITRE ATT&CK T1564 Hide Artifacts
- Microsoft Win32 — Reparse Points / Mount Points (NTFS junctions)
- Microsoft Win32 — Maximum Path Length Limitation (MAX_PATH / LongPathsEnabled)
- MITRE ATT&CK T1562.001 Impair Defenses: Disable or Modify Tools
- MITRE ATT&CK T1499 Endpoint Denial of Service
Detection coverage for TL-2026-0821
As of 2026-06-16, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-0821 across Splunk SPL, Microsoft KQL and Sigma, covering 18 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.