Windows Diskshadow.exe Child Process Execution
Alerts when Diskshadow.exe is the parent process of a newly created process on Windows.
- Product
- windows
- Category
- process_creation
- Author
- Harjot Singh @cyb3rjy0t (SigmaHQ), DRL 1.1
- Published
- 2023-09-15
- Updated
- 2026-07-31
ATT&CK techniques
Defense EvasionRecon
Resource Dev
Initial Access
Execution
Persistence
Priv Esc
Defense Evasion
Cred Access
Discovery
Lateral Movement
Collection
C2
Exfiltration
Impact
What it detects
This rule identifies process creation events where the parent process is Diskshadow.exe, indicating Diskshadow spawned a child application. Attackers may use Diskshadow’s interpreter or script modes with an exec flag to run additional binaries, making this parent-child relationship a useful stealth indicator. The detection relies on Windows process creation telemetry with parent process image paths and child image paths, including exclusion handling for WerFault.exe to reduce noise.
Reporting behind it
- bohops.comhttps://bohops.com/2018/03/26/diskshadow-the-return-of-vss-evasion-persistence-and-active-directory-database-extraction/
- ired.teamhttps://www.ired.team/offensive-security/credential-access-and-credential-dumping/ntds.dit-enumeration
- medium.comhttps://medium.com/@cyberjyot/lolbin-execution-via-diskshadow-f6ff681a27a4
- learn.microsoft.comhttps://learn.microsoft.com/en-us/windows-server/administration/windows-commands/diskshadow
- github.comhttps://github.com/SigmaHQ/sigma/blob/master/rules-threat-hunting/windows/process_creation/proc_creation_win_diskshadow_child_process.yml
Changelog
v5- v5Candidate ingested via manual entry.2026-07-31
- v4Candidate ingested via manual entry.2026-07-31
- v3Candidate ingested via manual entry.2026-07-31
- v2Candidate ingested via manual entry.2026-07-31
- v1No changelog recorded for this version.2026-07-30
Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.
title: Windows Diskshadow.exe Child Process Execution
id: f42fb570-418b-451d-9c97-5afe711f1ac9
related:
- id: fa1a7e52-3d02-435b-81b8-00da14dd66c1
type: similar
- id: 1dde5376-a648-492e-9e54-4241dd9b0c7f
type: similar
- id: 9f546b25-5f12-4c8d-8532-5893dcb1e4b8
type: similar
- id: 0c2f8629-7129-4a8a-9897-7e0768f13ff2
type: similar
- id: 56b1dde8-b274-435f-a73a-fb75eb81262a
type: derived
status: test
description: This rule identifies process creation events where the parent process is Diskshadow.exe, indicating Diskshadow spawned a child application. Attackers may use Diskshadow’s interpreter or script modes with an exec flag to run additional binaries, making this parent-child relationship a useful stealth indicator. The detection relies on Windows process creation telemetry with parent process image paths and child image paths, including exclusion handling for WerFault.exe to reduce noise.
references:
- https://bohops.com/2018/03/26/diskshadow-the-return-of-vss-evasion-persistence-and-active-directory-database-extraction/
- https://www.ired.team/offensive-security/credential-access-and-credential-dumping/ntds.dit-enumeration
- https://medium.com/@cyberjyot/lolbin-execution-via-diskshadow-f6ff681a27a4
- https://learn.microsoft.com/en-us/windows-server/administration/windows-commands/diskshadow
- https://github.com/SigmaHQ/sigma/blob/master/rules-threat-hunting/windows/process_creation/proc_creation_win_diskshadow_child_process.yml
author: Harjot Singh @cyb3rjy0t, Huntrule Team
date: 2023-09-15
tags:
- attack.stealth
- attack.t1218
- attack.execution
- detection.threat-hunting
logsource:
category: process_creation
product: windows
detection:
selection:
ParentImage|endswith: \diskshadow.exe
filter_main_werfault:
Image|endswith: :\Windows\System32\WerFault.exe
condition: selection and not 1 of filter_main_*
falsepositives:
- Likely from legitimate usage of Diskshadow in Interpreter mode.
level: medium
license: DRL-1.1