Windows Diskshadow Script Mode Execution via /s Flag
Alerts when Diskshadow is executed in script mode using the /s flag.
FreeUnreviewedSigmamediumv1
windows-diskshadow-script-mode-execution-via-s-flag-0c2f8629
title: Windows Diskshadow Script Mode Execution via /s Flag
id: f84f10b1-6b3d-40bc-81fb-1e08b8180b1c
related:
- id: fa1a7e52-3d02-435b-81b8-00da14dd66c1
type: similar
- id: 1dde5376-a648-492e-9e54-4241dd9b0c7f
type: similar
- id: 9f546b25-5f12-4c8d-8532-5893dcb1e4b8
type: similar
- id: 56b1dde8-b274-435f-a73a-fb75eb81262a
type: similar
- id: 0c2f8629-7129-4a8a-9897-7e0768f13ff2
type: derived
status: test
description: This rule flags process creation where diskshadow.exe is launched with the /s script-mode flag. Attackers can use Diskshadow to run script files that alter or remove Volume Shadow Copy data, enabling stealthy actions such as evasion or access to sensitive data. It relies on Windows process creation telemetry, matching OriginalFileName/Image path and the command line containing the '-s ' argument.
references:
- https://bohops.com/2018/03/26/diskshadow-the-return-of-vss-evasion-persistence-and-active-directory-database-extraction/
- https://www.ired.team/offensive-security/credential-access-and-credential-dumping/ntds.dit-enumeration
- https://medium.com/@cyberjyot/lolbin-execution-via-diskshadow-f6ff681a27a4
- https://learn.microsoft.com/en-us/windows-server/administration/windows-commands/diskshadow
- https://github.com/SigmaHQ/sigma/blob/master/rules-threat-hunting/windows/process_creation/proc_creation_win_diskshadow_script_mode.yml
author: Ivan Dyachkov, oscd.community, Huntrule Team
date: 2020-10-07
modified: 2024-03-13
tags:
- attack.stealth
- attack.t1218
- attack.execution
- detection.threat-hunting
logsource:
category: process_creation
product: windows
detection:
selection_img:
- OriginalFileName: diskshadow.exe
- Image|endswith: \diskshadow.exe
selection_cli:
CommandLine|contains|windash: "-s "
condition: all of selection_*
falsepositives:
- Likely from legitimate backup scripts
level: medium
license: DRL-1.1
What it detects
This rule flags process creation where diskshadow.exe is launched with the /s script-mode flag. Attackers can use Diskshadow to run script files that alter or remove Volume Shadow Copy data, enabling stealthy actions such as evasion or access to sensitive data. It relies on Windows process creation telemetry, matching OriginalFileName/Image path and the command line containing the '-s ' argument.
Known false positives
- Likely from legitimate backup scripts
Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.