Vshadow Logo

Vshadow

0
Free
Visit Website

Vshadow (vshadow.exe) is a command line utility for managing volume shadow copies included within the Windows SDK and signed by Microsoft. It allows for executing scripts and invoking commands in support of volume shadow snapshot management, which can be abused for privileged-level evasion, persistence, and file extraction. The tool supports the -exec parameter for executing binaries or scripts without command arguments.

FEATURES

ALTERNATIVES

A cybersecurity tool for collecting and analyzing forensic artifacts on live systems.

Recover event log entries from an image by heuristically looking for record structures.

Collects and organizes Linux OS data for detailed analysis and incident response.

Truehunter is a tool designed to detect encrypted containers with a focus on Truecrypt and Veracrypt, utilizing a fast and memory efficient approach.

CyLR is a Live Response Collection tool for quickly and securely collecting forensic artifacts from hosts with NTFS file systems.

A tool that uses Plaso to parse forensic artifacts and disk images, creating custom reports for easier analysis.

Automated collection tool for incident response triage in Windows systems.

Analyzing WiFiConfigStore.xml file for digital forensics on Android devices.

PINNED