Windows Diskshadow Script Mode (/s) Execution From Potentially Suspicious Paths

Alerts when diskshadow.exe runs with /s and a script path found in Temp/AppData/ProgramData/Users\Public-style directories.

FreeUnreviewedSigmamediumv1
title: Windows Diskshadow Script Mode (/s) Execution From Potentially Suspicious Paths
id: a0f68e15-a7df-4075-98a2-87e71c0683e0
related:
  - id: 1dde5376-a648-492e-9e54-4241dd9b0c7f
    type: similar
  - id: 9f546b25-5f12-4c8d-8532-5893dcb1e4b8
    type: similar
  - id: 56b1dde8-b274-435f-a73a-fb75eb81262a
    type: similar
  - id: 0c2f8629-7129-4a8a-9897-7e0768f13ff2
    type: similar
  - id: fa1a7e52-3d02-435b-81b8-00da14dd66c1
    type: derived
status: test
description: This rule flags process creation where diskshadow.exe is launched in script mode using the /s flag and the command line indicates the script resides in common but potentially suspicious locations (e.g., Temp, AppData, ProgramData, or Users\Public). Attackers may use Diskshadow’s script mode to automate VSS-related actions and execute from less-trusted filesystem paths to evade simple monitoring. Detection relies on Windows process creation telemetry with the process image path and command-line contents, including script location indicators.
references:
  - https://bohops.com/2018/03/26/diskshadow-the-return-of-vss-evasion-persistence-and-active-directory-database-extraction/
  - https://www.ired.team/offensive-security/credential-access-and-credential-dumping/ntds.dit-enumeration
  - https://medium.com/@cyberjyot/lolbin-execution-via-diskshadow-f6ff681a27a4
  - https://learn.microsoft.com/en-us/windows-server/administration/windows-commands/diskshadow
  - https://www.lifars.com/wp-content/uploads/2022/01/GriefRansomware_Whitepaper-2.pdf
  - https://www.zscaler.com/blogs/security-research/technical-analysis-crytox-ransomware
  - https://research.checkpoint.com/2022/evilplayout-attack-against-irans-state-broadcaster/
  - https://github.com/SigmaHQ/sigma/blob/master/rules/windows/process_creation/proc_creation_win_diskshadow_script_mode_susp_location.yml
author: Nasreddine Bencherchali (Nextron Systems), Huntrule Team
date: 2023-09-15
modified: 2024-03-05
tags:
  - attack.stealth
  - attack.t1218
logsource:
  category: process_creation
  product: windows
detection:
  selection_img:
    - OriginalFileName: diskshadow.exe
    - Image|endswith: \diskshadow.exe
  selection_cli:
    CommandLine|contains|windash: "-s "
  selection_paths:
    CommandLine|contains:
      - :\Temp\
      - :\Windows\Temp\
      - \AppData\Local\
      - \AppData\Roaming\
      - \ProgramData\
      - \Users\Public\
  condition: all of selection_*
falsepositives:
  - False positives may occur if you execute the script from one of the paths mentioned in the rule. Apply additional filters that fits your org needs.
level: medium
license: DRL-1.1

What it detects

This rule flags process creation where diskshadow.exe is launched in script mode using the /s flag and the command line indicates the script resides in common but potentially suspicious locations (e.g., Temp, AppData, ProgramData, or Users\Public). Attackers may use Diskshadow’s script mode to automate VSS-related actions and execute from less-trusted filesystem paths to evade simple monitoring. Detection relies on Windows process creation telemetry with the process image path and command-line contents, including script location indicators.

Known false positives

  • False positives may occur if you execute the script from one of the paths mentioned in the rule. Apply additional filters that fits your org needs.

Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.