Русский

Hidden and System Attributes in Windows

5 min 2026-10-01

Overview

In Windows, the Hidden (H) attribute marks a file or folder as hidden, while System (S) marks it as a system object. A file with H + S remains invisible in File Explorer even when hidden files are shown, if “Hide protected operating system files (Recommended)” is enabled.

Note

You can set System on an ordinary user file. This attribute is unrelated to the NT AUTHORITY\SYSTEM account and does not grant additional access rights.

Two File Explorer settings

To see H + S objects, press Win + R → control.exe folders → View:

  1. Select Show hidden files, folders, and drives.
  2. Clear Hide protected operating system files (Recommended) and confirm the Windows warning.
  3. Click Apply. If the file list has not refreshed, press F5 in File Explorer.

The Hidden items option in File Explorer (View → Show) controls only the first setting.

File Explorer options: hidden files and protected operating system files

File visibility with different settings:

Show hidden files “Hide protected operating system files” File without H or S File with H File with S File with H + S
Off Selected Visible Hidden Visible Hidden
On Selected Visible Visible Visible Hidden
On Cleared Visible Visible Visible Visible

Practical example

1. Create four test files

Run these commands in CMD. If %TEMP%\system-attribute-demo already exists, remove it (see Remove the test folder) or change the folder name in all the commands below.

mkdir "%TEMP%\system-attribute-demo"
cd /d "%TEMP%\system-attribute-demo"

echo Ordinary file>normal.txt
echo Hidden file>hidden.txt
echo System file>system-only.txt
echo Hidden and system file>hidden-system.txt

attrib +h "hidden.txt"
attrib +s "system-only.txt"
attrib +h +s "hidden-system.txt"

attrib

+ sets an attribute; - removes it. The attrib output may also include Archive (A), which does not affect visibility.

Creating four test files and setting their attributes in CMD

2. View the folder with default settings

Open the folder from the same CMD window:

explorer .

Turn off hidden file display and enable hiding protected operating system files (see Two File Explorer settings). Only normal.txt and system-only.txt will remain visible.

The test folder with default File Explorer settings

3. Show hidden files

Enable Hidden items (View → Show → Hidden items) while leaving protected operating system files hidden. hidden.txt appears, but hidden-system.txt remains hidden.

Hidden files shown while protected operating system files remain hidden

4. Show protected operating system files

In File Explorer Options → View, clear Hide protected operating system files (Recommended), confirm the Windows warning and click Apply. Leave hidden file display enabled. All four files are now visible.

The warning refers to files “marked as system or hidden”, but this checkbox affects only objects with both H and S set. Hidden file display controls hidden.txt; system-only.txt is visible with every combination of these settings.

All four test files visible after changing both File Explorer settings

Inspect files without changing File Explorer settings

Hiding a file in File Explorer does not change its access permissions. With the appropriate permissions, you can read the file using its known path.

CMD

From the test folder:

rem Show all files and folders, including hidden and system objects
dir /a

rem Show objects with the System attribute
dir /a:s

rem Show objects with both Hidden and System attributes
dir /a:hs

rem Inspect a specific file's attributes
attrib "hidden-system.txt"

rem Read the file using its known path
type "hidden-system.txt"

Listing all files with dir /a in CMD

Inspecting and reading a hidden system file in CMD

PowerShell

$demoPath = Join-Path $env:TEMP 'system-attribute-demo'

Get-ChildItem -LiteralPath $demoPath -Force |
    Select-Object Name, Attributes

To inspect one object:

Get-Item -LiteralPath (Join-Path $demoPath 'hidden-system.txt') -Force |
    Select-Object FullName, Attributes

-Force includes hidden and system objects in the results. The Attributes field for hidden-system.txt contains Hidden and System.

Inspecting file attributes in PowerShell

The equivalent of dir /a:hs uses -Attributes, where + means “and”:

Get-ChildItem -LiteralPath $demoPath -Attributes Hidden+System

Remove the attributes

In CMD, from the test folder, run:

attrib -s -h "hidden-system.txt"
attrib "hidden-system.txt"

Remove H and S together in one command. Removing them individually fails: attrib -h reports that it cannot reset a system file, and attrib -s reports that it cannot reset a hidden file.

Removing Hidden and System attributes together in CMD

After removing H and S, restore the default File Explorer settings: turn off hidden file display and enable hiding protected operating system files. hidden-system.txt remains visible. Its contents have not changed.

The file remains visible after its attributes are removed

Set folder attributes in the same way:

mkdir "demo-folder"
attrib +s +h "demo-folder"
attrib "demo-folder"
attrib -s -h "demo-folder"
attrib "demo-folder"

These commands change the folder's own attributes: attrib shows SH after +s +h, and an empty attributes field after -s -h. For recursive processing, attrib provides /S and /D.

Setting and removing attributes on a folder

Remove the test folder

CMD cannot remove its current working directory, so leave the folder first:

cd /d "%TEMP%"
rd /s /q "%TEMP%\system-attribute-demo"

rd /s removes the contents, including hidden and system files.

Warning

del without /a silently skips files with H or S attributes. In this test folder, del *.txt would remove only normal.txt and hidden-system.txt (after their attributes have been removed), leaving hidden.txt and system-only.txt. Use del /a *.txt to remove those too.

Use in attacks

H + S is a simple way to hide a file from a user: File Explorer does not show it with default settings, or even with Hidden items enabled. MITRE ATT&CK classifies this as T1564.001 (Hide Artifacts: Hidden Files and Directories).

Final demonstration

The screenshots and recordings show the original Russian Windows interface.

Original screenshots and recordings may contain Russian text.