Skip to content

DiskShadow Script Execution

Attackers abuse the signed Volume Shadow Copy utility diskshadow.exe, whose scripting language includes an exec command, as an unexpected LOLBin.

diskshadow.exe is a signed Windows utility for scripting Volume Shadow Copy Service (VSS) operations — creating, exposing and managing shadow copies for backup tooling. Its scripting language, run with /s scriptfile, is more capable than its narrow purpose suggests: it includes an exec command that runs an arbitrary external program. An analyst who only thinks of diskshadow.exe in the context of shadow-copy deletion (already covered as shadow copy deletion elsewhere in this catalog) can miss it entirely as a code-execution vector in its own right.

How it works

The attacker drops a small script and points diskshadow at it:

text
diskshadow.exe /s C:\Users\Public\run.txt
text
# run.txt
exec "cmd.exe" /c calc.exe

diskshadow parses the script, reaches the exec line, and launches the named program as a child process — no VSS operation needs to actually occur. Because diskshadow.exe is signed and rarely monitored as an execution vector, this proxies a command through a binary defenders associate with backup and shadow-copy housekeeping, not code execution.

Detection & analysis

Static analysis:

  • Any recovered diskshadow script file containing an exec line naming a command interpreter or non-backup-related binary is unambiguous — legitimate backup scripts use create, expose, delete shadows and similar VSS-management verbs, not exec.

Dynamic analysis:

  • Watch the process tree: diskshadow.exe spawning cmd.exe, powershell.exe, or an unrelated binary is not a pattern that occurs during normal backup-software use of the tool.
  • Correlate with actual VSS state — if exec fires without any shadow copy having been created or exposed in the same script, the "backup" framing is a pretext.

Detection rule hint:

Alert on Sysmon Event ID 1 where Image ends with \diskshadow.exe AND the command line contains /s, correlated with a child-process creation event (Event ID 1 with ParentImage = diskshadow.exe) for any interpreter or unexpected binary — legitimate diskshadow scripts never spawn child processes.

Votes

Comments(0)