Windows Diskshadow Script Mode Execution with Uncommon Script Extension

Alerts when diskshadow.exe runs with -s script mode and the script path/command includes an uncommon extension like .txt.

FreeUnreviewedSigmamediumv1
title: Windows Diskshadow Script Mode Execution with Uncommon Script Extension
id: 9ec308d0-e715-4c7e-a5a6-62e12e66f2f2
related:
  - id: fa1a7e52-3d02-435b-81b8-00da14dd66c1
    type: similar
  - id: 9f546b25-5f12-4c8d-8532-5893dcb1e4b8
    type: similar
  - id: 56b1dde8-b274-435f-a73a-fb75eb81262a
    type: similar
  - id: 0c2f8629-7129-4a8a-9897-7e0768f13ff2
    type: similar
  - id: 1dde5376-a648-492e-9e54-4241dd9b0c7f
    type: derived
status: test
description: This rule flags process creation events where Diskshadow is run in script mode (via a command-line windash -s parameter) and the command line contains a potentially uncommon script extension (currently .txt). Attackers may use Diskshadow’s scripting capability to automate operations and blend into administrative tooling behavior. It relies on Windows process creation telemetry, including the OriginalFileName/Image path and the full command line string.
references:
  - https://bohops.com/2018/03/26/diskshadow-the-return-of-vss-evasion-persistence-and-active-directory-database-extraction/
  - https://www.ired.team/offensive-security/credential-access-and-credential-dumping/ntds.dit-enumeration
  - https://medium.com/@cyberjyot/lolbin-execution-via-diskshadow-f6ff681a27a4
  - https://learn.microsoft.com/en-us/windows-server/administration/windows-commands/diskshadow
  - https://www.lifars.com/wp-content/uploads/2022/01/GriefRansomware_Whitepaper-2.pdf
  - https://www.zscaler.com/blogs/security-research/technical-analysis-crytox-ransomware
  - https://research.checkpoint.com/2022/evilplayout-attack-against-irans-state-broadcaster/
  - https://github.com/SigmaHQ/sigma/blob/master/rules/windows/process_creation/proc_creation_win_diskshadow_script_mode_susp_ext.yml
author: Nasreddine Bencherchali (Nextron Systems), Huntrule Team
date: 2023-09-15
modified: 2024-03-05
tags:
  - attack.stealth
  - attack.t1218
logsource:
  category: process_creation
  product: windows
detection:
  selection_img:
    - OriginalFileName: diskshadow.exe
    - Image|endswith: \diskshadow.exe
  selection_flag:
    CommandLine|contains|windash: "-s "
  filter_main_ext:
    CommandLine|contains: .txt
  condition: all of selection_* and not 1 of filter_main_*
falsepositives:
  - False postitve might occur with legitimate or uncommon extensions used internally. Initial baseline is required.
level: medium
license: DRL-1.1

What it detects

This rule flags process creation events where Diskshadow is run in script mode (via a command-line windash -s parameter) and the command line contains a potentially uncommon script extension (currently .txt). Attackers may use Diskshadow’s scripting capability to automate operations and blend into administrative tooling behavior. It relies on Windows process creation telemetry, including the OriginalFileName/Image path and the full command line string.

Known false positives

  • False postitve might occur with legitimate or uncommon extensions used internally. Initial baseline is required.

Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.