DiskShadow Logo

DiskShadow

0
Free
Visit Website

DiskShadow.exe is a tool that exposes the functionality offered by the Volume Shadow Copy Service (VSS). By default, DiskShadow uses an interactive command interpreter similar to that of DiskRaid or DiskPart. DiskShadow also includes a scriptable mode. DiskShadow is included in Windows Server 2008, Windows Server 2012, and Windows Server 2019. It allows for the creation, enumeration, and manipulation of volume shadow copies. DiskShadow also includes features for persistence and evasion, making it a useful tool for offensive security operations. IOCs for defensive considerations include the creation of suspicious volume shadow copies and the use of DiskShadow for malicious purposes. In this post, we will discuss DiskShadow, present relevant features and capabilities for offensive opportunities, and highlight IOCs for defensive considerations.

FEATURES

ALTERNATIVES

Comprehensive host-survey tool for security checks in C#.

Emulate offensive attack techniques in the cloud with a self-contained Go binary.

Tool for enumerating proxy configurations and generating CobaltStrike-compatible shellcode.

Wfuzz is a tool designed for bruteforcing Web Applications with multiple features like multiple injection points, recursion, and payload combinations.

A tool for detecting and taking over subdomains with dead DNS records

A cheat sheet providing examples of creating reverse shells for penetration testing.

A tool for automated security scanning of web applications and manual penetration testing.

AzureC2Relay enhances security by validating and relaying Cobalt Strike beacon traffic through Azure Functions.

PINNED

CyberSecTools logoCyberSecTools

Explore the largest curated directory of cybersecurity tools and resources to enhance your security practices. Find the right solution for your domain.

Copyright © 2025 - All rights reserved