Windows Diskshadow Script Mode Execution via /s Flag

Alerts when Diskshadow is executed in script mode using the /s flag.

FreeUnreviewedSigmamediumv1
title: Windows Diskshadow Script Mode Execution via /s Flag
id: f84f10b1-6b3d-40bc-81fb-1e08b8180b1c
related:
  - id: fa1a7e52-3d02-435b-81b8-00da14dd66c1
    type: similar
  - id: 1dde5376-a648-492e-9e54-4241dd9b0c7f
    type: similar
  - id: 9f546b25-5f12-4c8d-8532-5893dcb1e4b8
    type: similar
  - id: 56b1dde8-b274-435f-a73a-fb75eb81262a
    type: similar
  - id: 0c2f8629-7129-4a8a-9897-7e0768f13ff2
    type: derived
status: test
description: This rule flags process creation where diskshadow.exe is launched with the /s script-mode flag. Attackers can use Diskshadow to run script files that alter or remove Volume Shadow Copy data, enabling stealthy actions such as evasion or access to sensitive data. It relies on Windows process creation telemetry, matching OriginalFileName/Image path and the command line containing the '-s ' argument.
references:
  - https://bohops.com/2018/03/26/diskshadow-the-return-of-vss-evasion-persistence-and-active-directory-database-extraction/
  - https://www.ired.team/offensive-security/credential-access-and-credential-dumping/ntds.dit-enumeration
  - https://medium.com/@cyberjyot/lolbin-execution-via-diskshadow-f6ff681a27a4
  - https://learn.microsoft.com/en-us/windows-server/administration/windows-commands/diskshadow
  - https://github.com/SigmaHQ/sigma/blob/master/rules-threat-hunting/windows/process_creation/proc_creation_win_diskshadow_script_mode.yml
author: Ivan Dyachkov, oscd.community, Huntrule Team
date: 2020-10-07
modified: 2024-03-13
tags:
  - attack.stealth
  - attack.t1218
  - attack.execution
  - detection.threat-hunting
logsource:
  category: process_creation
  product: windows
detection:
  selection_img:
    - OriginalFileName: diskshadow.exe
    - Image|endswith: \diskshadow.exe
  selection_cli:
    CommandLine|contains|windash: "-s "
  condition: all of selection_*
falsepositives:
  - Likely from legitimate backup scripts
level: medium
license: DRL-1.1

What it detects

This rule flags process creation where diskshadow.exe is launched with the /s script-mode flag. Attackers can use Diskshadow to run script files that alter or remove Volume Shadow Copy data, enabling stealthy actions such as evasion or access to sensitive data. It relies on Windows process creation telemetry, matching OriginalFileName/Image path and the command line containing the '-s ' argument.

Known false positives

  • Likely from legitimate backup scripts

Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.