Windows: Diskshadow.exe Script Mode Execution from Suspicious File Paths
Alerts when diskshadow.exe runs with /s and a script path found in Temp/AppData/ProgramData/Users\Public-style directories.
- Product
- windows
- Category
- process_creation
- Author
- Nasreddine Bencherchali (Nextron Systems) (SigmaHQ), DRL 1.1
- Published
- 2023-09-15
- Updated
- 2026-07-31
ATT&CK techniques
Defense EvasionRecon
Resource Dev
Initial Access
Execution
Persistence
Priv Esc
Defense Evasion
Cred Access
Discovery
Lateral Movement
Collection
C2
Exfiltration
Impact
What it detects
This rule flags process creation events where Diskshadow.exe is executed in script mode using the /s flag while the script path appears to be located in commonly abused or suspicious directories. Attackers can use Diskshadow to run scripted actions for stealthy persistence and sensitive data access, so constraining script execution locations helps surface suspicious usage patterns. It relies on Windows process creation telemetry including OriginalFileName/Image path and the command line containing the /s parameter and target script location substrings.
Reporting behind it
- bohops.comhttps://bohops.com/2018/03/26/diskshadow-the-return-of-vss-evasion-persistence-and-active-directory-database-extraction/
- ired.teamhttps://www.ired.team/offensive-security/credential-access-and-credential-dumping/ntds.dit-enumeration
- medium.comhttps://medium.com/@cyberjyot/lolbin-execution-via-diskshadow-f6ff681a27a4
- learn.microsoft.comhttps://learn.microsoft.com/en-us/windows-server/administration/windows-commands/diskshadow
- lifars.comhttps://www.lifars.com/wp-content/uploads/2022/01/GriefRansomware_Whitepaper-2.pdf
- zscaler.comhttps://www.zscaler.com/blogs/security-research/technical-analysis-crytox-ransomware
- research.checkpoint.comhttps://research.checkpoint.com/2022/evilplayout-attack-against-irans-state-broadcaster/
- github.comhttps://github.com/SigmaHQ/sigma/blob/master/rules/windows/process_creation/proc_creation_win_diskshadow_script_mode_susp_location.yml
Changelog
v2- v2Candidate ingested via manual entry.2026-07-31
- v1No changelog recorded for this version.2026-07-30
Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.
title: "Windows: Diskshadow.exe Script Mode Execution from Suspicious File Paths"
id: a0f68e15-a7df-4075-98a2-87e71c0683e0
related:
- id: 1dde5376-a648-492e-9e54-4241dd9b0c7f
type: similar
- id: 9f546b25-5f12-4c8d-8532-5893dcb1e4b8
type: similar
- id: 56b1dde8-b274-435f-a73a-fb75eb81262a
type: similar
- id: 0c2f8629-7129-4a8a-9897-7e0768f13ff2
type: similar
- id: fa1a7e52-3d02-435b-81b8-00da14dd66c1
type: derived
status: test
description: This rule flags process creation events where Diskshadow.exe is executed in script mode using the /s flag while the script path appears to be located in commonly abused or suspicious directories. Attackers can use Diskshadow to run scripted actions for stealthy persistence and sensitive data access, so constraining script execution locations helps surface suspicious usage patterns. It relies on Windows process creation telemetry including OriginalFileName/Image path and the command line containing the /s parameter and target script location substrings.
references:
- https://bohops.com/2018/03/26/diskshadow-the-return-of-vss-evasion-persistence-and-active-directory-database-extraction/
- https://www.ired.team/offensive-security/credential-access-and-credential-dumping/ntds.dit-enumeration
- https://medium.com/@cyberjyot/lolbin-execution-via-diskshadow-f6ff681a27a4
- https://learn.microsoft.com/en-us/windows-server/administration/windows-commands/diskshadow
- https://www.lifars.com/wp-content/uploads/2022/01/GriefRansomware_Whitepaper-2.pdf
- https://www.zscaler.com/blogs/security-research/technical-analysis-crytox-ransomware
- https://research.checkpoint.com/2022/evilplayout-attack-against-irans-state-broadcaster/
- https://github.com/SigmaHQ/sigma/blob/master/rules/windows/process_creation/proc_creation_win_diskshadow_script_mode_susp_location.yml
author: Nasreddine Bencherchali (Nextron Systems), Huntrule Team
date: 2023-09-15
modified: 2024-03-05
tags:
- attack.stealth
- attack.t1218
logsource:
category: process_creation
product: windows
detection:
selection_img:
- OriginalFileName: diskshadow.exe
- Image|endswith: \diskshadow.exe
selection_cli:
CommandLine|contains|windash: "-s "
selection_paths:
CommandLine|contains:
- :\Temp\
- :\Windows\Temp\
- \AppData\Local\
- \AppData\Roaming\
- \ProgramData\
- \Users\Public\
condition: all of selection_*
falsepositives:
- False positives may occur if you execute the script from one of the paths mentioned in the rule. Apply additional filters that fits your org needs.
level: medium
license: DRL-1.1