Windows: Diskshadow.exe Script Mode Execution from Suspicious File Paths

Alerts when diskshadow.exe runs with /s and a script path found in Temp/AppData/ProgramData/Users\Public-style directories.

FreeReviewedSigma · Medium · v2
Product
windows
Category
process_creation
Author
Nasreddine Bencherchali (Nextron Systems) (SigmaHQ), DRL 1.1
Published
2023-09-15
Updated
2026-07-31
title: "Windows: Diskshadow.exe Script Mode Execution from Suspicious File Paths"
id: a0f68e15-a7df-4075-98a2-87e71c0683e0
related:
  - id: 1dde5376-a648-492e-9e54-4241dd9b0c7f
    type: similar
  - id: 9f546b25-5f12-4c8d-8532-5893dcb1e4b8
    type: similar
  - id: 56b1dde8-b274-435f-a73a-fb75eb81262a
    type: similar
  - id: 0c2f8629-7129-4a8a-9897-7e0768f13ff2
    type: similar
  - id: fa1a7e52-3d02-435b-81b8-00da14dd66c1
    type: derived
status: test
description: This rule flags process creation events where Diskshadow.exe is executed in script mode using the /s flag while the script path appears to be located in commonly abused or suspicious directories. Attackers can use Diskshadow to run scripted actions for stealthy persistence and sensitive data access, so constraining script execution locations helps surface suspicious usage patterns. It relies on Windows process creation telemetry including OriginalFileName/Image path and the command line containing the /s parameter and target script location substrings.
references:
  - https://bohops.com/2018/03/26/diskshadow-the-return-of-vss-evasion-persistence-and-active-directory-database-extraction/
  - https://www.ired.team/offensive-security/credential-access-and-credential-dumping/ntds.dit-enumeration
  - https://medium.com/@cyberjyot/lolbin-execution-via-diskshadow-f6ff681a27a4
  - https://learn.microsoft.com/en-us/windows-server/administration/windows-commands/diskshadow
  - https://www.lifars.com/wp-content/uploads/2022/01/GriefRansomware_Whitepaper-2.pdf
  - https://www.zscaler.com/blogs/security-research/technical-analysis-crytox-ransomware
  - https://research.checkpoint.com/2022/evilplayout-attack-against-irans-state-broadcaster/
  - https://github.com/SigmaHQ/sigma/blob/master/rules/windows/process_creation/proc_creation_win_diskshadow_script_mode_susp_location.yml
author: Nasreddine Bencherchali (Nextron Systems), Huntrule Team
date: 2023-09-15
modified: 2024-03-05
tags:
  - attack.stealth
  - attack.t1218
logsource:
  category: process_creation
  product: windows
detection:
  selection_img:
    - OriginalFileName: diskshadow.exe
    - Image|endswith: \diskshadow.exe
  selection_cli:
    CommandLine|contains|windash: "-s "
  selection_paths:
    CommandLine|contains:
      - :\Temp\
      - :\Windows\Temp\
      - \AppData\Local\
      - \AppData\Roaming\
      - \ProgramData\
      - \Users\Public\
  condition: all of selection_*
falsepositives:
  - False positives may occur if you execute the script from one of the paths mentioned in the rule. Apply additional filters that fits your org needs.
level: medium
license: DRL-1.1