Skip to content

Hide Navigation Hide TOC

Diskshadow Script Mode - Uncommon Script Extension Execution (1dde5376-a648-492e-9e54-4241dd9b0c7f)

Detects execution of "Diskshadow.exe" in script mode to execute an script with a potentially uncommon extension. Initial baselining of the allowed extension list is required.

Cluster A Galaxy A Cluster B Galaxy B Level
System Binary Proxy Execution - T1218 (457c7820-d331-465a-915e-42f85500ccc4) Attack Pattern Diskshadow Script Mode - Uncommon Script Extension Execution (1dde5376-a648-492e-9e54-4241dd9b0c7f) Sigma-Rules 1