DiskShadow Script Execution
Attackers abuse the signed Volume Shadow Copy utility diskshadow.exe, whose scripting language includes an exec command, as an unexpected LOLBin.
diskshadow.exe is a signed Windows utility for scripting Volume Shadow Copy
Service (VSS) operations — creating, exposing and managing shadow copies for
backup tooling. Its scripting language, run with /s scriptfile, is more
capable than its narrow purpose suggests: it includes an exec command that
runs an arbitrary external program. An analyst who only thinks of
diskshadow.exe in the context of shadow-copy deletion (already covered as
shadow copy deletion elsewhere in this
catalog) can miss it entirely as a code-execution vector in its own right.
How it works
The attacker drops a small script and points diskshadow at it:
diskshadow.exe /s C:\Users\Public\run.txt# run.txt
exec "cmd.exe" /c calc.exediskshadow parses the script, reaches the exec line, and launches the
named program as a child process — no VSS operation needs to actually occur.
Because diskshadow.exe is signed and rarely monitored as an execution
vector, this proxies a command through a binary defenders associate with
backup and shadow-copy housekeeping, not code execution.
Detection & analysis
Static analysis:
- Any recovered
diskshadowscript file containing anexecline naming a command interpreter or non-backup-related binary is unambiguous — legitimate backup scripts usecreate,expose,delete shadowsand similar VSS-management verbs, notexec.
Dynamic analysis:
- Watch the process tree:
diskshadow.exespawningcmd.exe,powershell.exe, or an unrelated binary is not a pattern that occurs during normal backup-software use of the tool. - Correlate with actual VSS state — if
execfires without any shadow copy having been created or exposed in the same script, the "backup" framing is a pretext.
Detection rule hint:
Alert on Sysmon Event ID 1 where Image ends with \diskshadow.exe AND the
command line contains /s, correlated with a child-process creation event
(Event ID 1 with ParentImage = diskshadow.exe) for any interpreter or
unexpected binary — legitimate diskshadow scripts never spawn child
processes.