An Introduction to the exFAT File System and How to Hide Data Within


  • Julian Heeger Fraunhofer SIT, Germany
  • York Yannikos Fraunhofer SIT, Germany
  • Martin Steinebach Fraunhofer SIT, Germany



data hiding, file systems, anti forensic


In the recent years steganographic techniques for hiding data in file system metadata gained focus. While commonly used file systems received tooling and publications the exFAT file system did not get much attention – probably because its structure provides only few suitable locations to hide data. In this work we present an overview of exFAT’s internals and describe the different structures used by the file system to store files. We also introduce two approaches that allow us to embed messages into the exFAT file system using steganographic techniques. The first approach has a lower embedding rate, but has less specific requirements for the embedding location. The other one, called exHide, uses error correcting to allow for an more robust approach. Both approaches are specified, evaluated and discussed in terms of their strengths and weaknesses.


Author Biographies

Julian Heeger, Fraunhofer SIT, Germany

Julian Heeger became a researcher in cybersecurity at the Media Security and IT Forensics department of Fraunhofer SIT, after he completed his master’s degree in IT security at the Technical University of Darmstadt.

York Yannikos, Fraunhofer SIT, Germany

York Yannikos is a Research Associate at the Fraunhofer Institute for Secure Information Technology, Darmstadt, Germany. His research interests include digital forensic tool testing, darknet marketplaces, and open source intelligence.

Martin Steinebach, Fraunhofer SIT, Germany

Martin Steinebach. Prof. Dr. Martin Steinebach is the manager of the Media Security and IT Forensics division at Fraunhofer SIT. From 2003 to 2007 he was the manager of the Media Security in IT division at Fraunhofer IPSI. He studied computer science at the Technical University of Darmstadt and finished his diploma thesis on copyright protection for digital audio in 1999. In 2003 he received his PhD at the Technical University of Darmstadt for this work on digital audio watermarking. In 2016 he became honorary professor at the TU Darmstadt. He gives lectures on Multimedia Security as well as Civil Security. He is Principle Investigator at ATHENE and represents IT Forensics and AI Security. Before he was Principle Investigator at CASED with the topics Multimedia Security and IT Forensics.


