Windows Diskshadow Script Mode Execution with Uncommon Script Extension
Alerts when diskshadow.exe runs with -s script mode and the script path/command includes an uncommon extension like .txt.
FreeUnreviewedSigmamediumv1
windows-diskshadow-script-mode-execution-with-uncommon-script-extension-1dde5376
title: Windows Diskshadow Script Mode Execution with Uncommon Script Extension
id: 9ec308d0-e715-4c7e-a5a6-62e12e66f2f2
related:
- id: fa1a7e52-3d02-435b-81b8-00da14dd66c1
type: similar
- id: 9f546b25-5f12-4c8d-8532-5893dcb1e4b8
type: similar
- id: 56b1dde8-b274-435f-a73a-fb75eb81262a
type: similar
- id: 0c2f8629-7129-4a8a-9897-7e0768f13ff2
type: similar
- id: 1dde5376-a648-492e-9e54-4241dd9b0c7f
type: derived
status: test
description: This rule flags process creation events where Diskshadow is run in script mode (via a command-line windash -s parameter) and the command line contains a potentially uncommon script extension (currently .txt). Attackers may use Diskshadow’s scripting capability to automate operations and blend into administrative tooling behavior. It relies on Windows process creation telemetry, including the OriginalFileName/Image path and the full command line string.
references:
- https://bohops.com/2018/03/26/diskshadow-the-return-of-vss-evasion-persistence-and-active-directory-database-extraction/
- https://www.ired.team/offensive-security/credential-access-and-credential-dumping/ntds.dit-enumeration
- https://medium.com/@cyberjyot/lolbin-execution-via-diskshadow-f6ff681a27a4
- https://learn.microsoft.com/en-us/windows-server/administration/windows-commands/diskshadow
- https://www.lifars.com/wp-content/uploads/2022/01/GriefRansomware_Whitepaper-2.pdf
- https://www.zscaler.com/blogs/security-research/technical-analysis-crytox-ransomware
- https://research.checkpoint.com/2022/evilplayout-attack-against-irans-state-broadcaster/
- https://github.com/SigmaHQ/sigma/blob/master/rules/windows/process_creation/proc_creation_win_diskshadow_script_mode_susp_ext.yml
author: Nasreddine Bencherchali (Nextron Systems), Huntrule Team
date: 2023-09-15
modified: 2024-03-05
tags:
- attack.stealth
- attack.t1218
logsource:
category: process_creation
product: windows
detection:
selection_img:
- OriginalFileName: diskshadow.exe
- Image|endswith: \diskshadow.exe
selection_flag:
CommandLine|contains|windash: "-s "
filter_main_ext:
CommandLine|contains: .txt
condition: all of selection_* and not 1 of filter_main_*
falsepositives:
- False postitve might occur with legitimate or uncommon extensions used internally. Initial baseline is required.
level: medium
license: DRL-1.1
What it detects
This rule flags process creation events where Diskshadow is run in script mode (via a command-line windash -s parameter) and the command line contains a potentially uncommon script extension (currently .txt). Attackers may use Diskshadow’s scripting capability to automate operations and blend into administrative tooling behavior. It relies on Windows process creation telemetry, including the OriginalFileName/Image path and the full command line string.
Known false positives
- False postitve might occur with legitimate or uncommon extensions used internally. Initial baseline is required.
Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.