DiskShadow Logo

DiskShadow

0
Free
Visit Website

DiskShadow.exe is a tool that exposes the functionality offered by the Volume Shadow Copy Service (VSS). By default, DiskShadow uses an interactive command interpreter similar to that of DiskRaid or DiskPart. DiskShadow also includes a scriptable mode. DiskShadow is included in Windows Server 2008, Windows Server 2012, and Windows Server 2019. It allows for the creation, enumeration, and manipulation of volume shadow copies. DiskShadow also includes features for persistence and evasion, making it a useful tool for offensive security operations. IOCs for defensive considerations include the creation of suspicious volume shadow copies and the use of DiskShadow for malicious purposes. In this post, we will discuss DiskShadow, present relevant features and capabilities for offensive opportunities, and highlight IOCs for defensive considerations.

FEATURES

ALTERNATIVES

A tool for interacting with Exchange servers remotely and exploiting client-side Outlook features.

A suite of tools for Wi-Fi network security assessment and penetration testing.

A week-long series of articles and talks on evading Microsoft Advanced Threat Analytics (ATA) detection

A payload creation framework designed to bypass Endpoint Detection and Response (EDR) systems.

Introduction to using GScript for Red Teams

A proof-of-concept obfuscation toolkit for C# post-exploitation tools, designed to conceal malicious activities from detection.

A tool for testing Cross Site Scripting vulnerabilities

Pupy is a cross-platform C2 and post-exploitation framework for remote access and control of compromised systems across various operating systems.

CyberSecTools logoCyberSecTools

Explore the largest curated directory of cybersecurity tools and resources to enhance your security practices. Find the right solution for your domain.

Copyright © 2024 - All rights reserved