# GhostTree / GhostBranch: Recursive NTFS Directory Junctions Abused to Evade Recursive File Scanners and Hide Malware

> GhostTree (and its single-junction variant GhostBranch) abuses legitimate Windows NTFS directory junctions to manufacture an astronomically large number of valid file paths that all resolve to the same location, causing recursive directory scanners — including Windows Defender and EDR products — to loop, hang, or skip files and leave co-located malware unscanned. The technique requires only standard-user write permissions (mklink /J). Microsoft initially closed the report as 'not crossing a security boundary' before patching the underlying recursive-scan behavior.

- **Published:** 2026-06-16T00:00:00Z
- **Last reviewed:** 2026-06-16T00:00:00Z
- **Canonical:** https://intel.threadlinqs.com/threat/TL-2026-0821
- **ID:** TL-2026-0821
- **Severity:** MEDIUM
- **Category:** THREAT_INTEL
- **Status:** PATCHED
- **Detections:** 9 · **IOCs:** 18 (full data via the Threadlinqs MCP server — Purple tier)

## Description

GhostTree is a Windows defense-evasion technique disclosed by Varonis Threat Labs (researcher Dolev Taler) on 2026-06-16. It weaponizes NTFS directory junctions — reparse points (IO_REPARSE_TAG_MOUNT_POINT) that transparently redirect directory access — to create self-referential, recursive directory loops on disk.

The simpler variant, GhostBranch, uses a single junction that points a child directory back at its own parent: `mklink /J C:\Parent\Child C:\Parent`. Because the junction resolves to its ancestor, the file system exposes an endless ladder of valid paths to the same file: C:\Parent\Child\Program.exe, C:\Parent\Child\Child\Program.exe, and so on. Any tool that walks the directory tree recursively will keep descending into the loop and never terminate.

GhostTree amplifies this by creating multiple child junctions at each level that each point back to the parent (e.g. `mklink /J C:\Parent\Child1 C:\Parent` and `mklink /J C:\Parent\Child2 C:\Parent`), producing a branching tree. Varonis calculates that with binary branching constrained by Windows' path-length limits the structure yields roughly 2^126 ≈ 8.5 × 10^37 distinct valid paths to a single executable — vastly more than the estimated number of grains of sand on Earth (~8.5 × 10^18).

Windows enforces a traditional maximum path length (MAX_PATH) of 260 characters, which caps recursion at approximately 126 nested directory levels when single-character folder names are used. This limit can be raised to 32,767 characters via the LongPathsEnabled registry value, though many applications and utilities still cannot handle paths beyond 260, so attackers can use the legacy limit while still defeating scanners.

The security impact is on recursive directory traversal. Varonis tested the technique against Windows Defender (Microsoft Defender Antivirus) and confirmed it could evade folder scans: the scanning engine becomes consumed following the directory loop and ultimately hangs without completing, so malware placed alongside the junctions remains unscanned and undetected by the endpoint agent. The same failure mode affects EDR products that perform unbounded recursive directory scans. This behaves as a denial-of-service against the security scanner itself, providing cover for arbitrary co-located payloads.

The technique is notable because it requires only standard write permissions rather than administrative privileges — any low-privileged user (or a foothold process) can create junctions with the built-in mklink utility or the CreateSymbolicLink / DeviceIoControl(FSCTL_SET_REPARSE_POINT) APIs. Varonis reported the issue to Microsoft, who initially closed the ticket with the explanation that 'bypassing Defender is not crossing a security boundary,' but Microsoft subsequently patched the recursive-scanning behavior regardless.

No CVE was assigned. No in-the-wild exploitation, malware family, threat-actor attribution, or network indicators (C2 IPs, domains, or file hashes) were reported in the source material; consequently there is no network infrastructure to correlate (BeaconBeagle pivot is not applicable). The indicators below are behavioral/host-based artifacts of the technique itself. Defenders are advised to monitor file-system activity at the data layer — anomalous junction/reparse-point creation and recursive directory structures that should not exist under normal operation — rather than relying solely on recursive native scanning, and to apply current Microsoft Defender platform updates.

## MITRE ATT&CK

- T1059 Command and Scripting Interpreter
- T1059.003 Windows Command Shell
- T1106 Native API
- T1564 Hide Artifacts
- T1564.004 NTFS File Attributes
- T1027 Obfuscated Files or Information
- T1036 Masquerading
- T1036.005 Match Legitimate Resource Name or Location
- T1685 Disable or Modify Tools
- T1112 Modify Registry
- T1070 Indicator Removal
- T1070.004 File Deletion
- T1059.001 PowerShell
- T1499 Endpoint Denial of Service

## Sources

- [GhostTree: Unveiling Path Manipulation Techniques to Bypass Windows Security (Varonis Threat Labs)](https://www.varonis.com/blog/ghosttree-ntfs-trick)
- [GhostTree attack abused recursive Windows junctions to hide malware (BleepingComputer)](https://www.bleepingcomputer.com/news/security/ghosttree-attack-abused-recursive-windows-junctions-to-hide-malware/)
- [New GhostTree Attack Causing EDR Products to Hang and Leave Files Unscanned (Cyber Security News)](https://cybersecuritynews.com/ghosttree-attack-edr-products/)
- [New GhostTree Attack Causes EDR Tools to Hang, Leaving Files Unscanned (GBHackers)](https://gbhackers.com/new-ghosttree-attack-causes-edr-tools/)
- [GhostTree Attack Causes EDR Tools to Hang, Skip File Scans (CyberPress)](https://cyberpress.org/ghosttree-attack-edr-tools/)
- [MITRE ATT&CK T1564 Hide Artifacts](https://attack.mitre.org/techniques/T1564/)
- [Microsoft Win32 — Reparse Points / Mount Points (NTFS junctions)](https://learn.microsoft.com/en-us/windows/win32/fileio/reparse-points)
- [Microsoft Win32 — Maximum Path Length Limitation (MAX_PATH / LongPathsEnabled)](https://learn.microsoft.com/en-us/windows/win32/fileio/maximum-file-path-limitation)
- [MITRE ATT&CK T1562.001 Impair Defenses: Disable or Modify Tools](https://attack.mitre.org/techniques/T1562/001/)
- [MITRE ATT&CK T1499 Endpoint Denial of Service](https://attack.mitre.org/techniques/T1499/)

## Full data

Detection queries (Splunk SPL / Microsoft KQL / Sigma) and IOC values require the Threadlinqs MCP server (Purple tier): https://intel.threadlinqs.com/mcp

Canonical: https://intel.threadlinqs.com/threat/TL-2026-0821
