[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$fZEo94m1brhRqTBqsIKsK3pTgSa_A74ci4K2Cpseo2N0":3},{"id":4,"question":5,"answer":6,"answerHtml":7,"slug":8,"keywords":9,"article":10,"status":34,"aiModel":39,"aiConfidence":39,"updatedAt":51,"createdAt":51,"_status":50},1028,"How can the `vshadow` tool be obtained, and why is it useful in penetration testing?","The `vshadow` tool is not included by default in Windows; it can be obtained from the Microsoft Windows SDK (e.g., version 7.2 for Server 2003\u002FXP, or SDK for Server 2008 R2\u002F7). It is useful because it allows manual creation of [Volume Shadow Copies](\u002Fnews\u002Fvolume-shadow-copy-in-penetration-testing) from the command line, enabling attackers to either copy locked files (like NTDS.dit) or launch binaries that disappear after deletion of the shadow copy and symbolic link.","\u003Cp>The `vshadow` tool is not included by default in Windows; it can be obtained from the Microsoft Windows SDK (e.g., version 7.2 for Server 2003\u002FXP, or SDK for Server 2008 R2\u002F7). It is useful because it allows manual creation of [Volume Shadow Copies](\u002Fnews\u002Fvolume-shadow-copy-in-penetration-testing) from the command line, enabling attackers to either copy locked files (like NTDS.dit) or launch binaries that disappear after deletion of the shadow copy and symbolic link.\u003C\u002Fp>\u003Cp>\u003Ca href=\"\u002Fnews\u002Fvolume-shadow-copy-in-penetration-testing\">Read the related One Day Sec article\u003C\u002Fa>\u003C\u002Fp>","how-can-the-vshadow-tool-be-obtained-and-why-is-it-useful-in-penetration-testing-1777480712216","vshadow, Microsoft SDK, Volume Shadow Copy, manual creation, NTDS.dit",{"id":11,"title":12,"slug":13,"description":14,"content":15,"contentHtml":30,"cover":31,"author":32,"views":19,"readingTime":33,"status":34,"publishedAt":35,"seo":36,"tags":41,"qaPairs":42,"meta":47,"updatedAt":48,"createdAt":49,"_status":50},251,"Volume Shadow Copy in Penetration Testing","volume-shadow-copy-in-penetration-testing","Learn how to exploit Volume Shadow Copy for file recovery and creating fileless processes in penetration testing, including commands and techniques.",{"root":16},{"type":17,"format":18,"indent":19,"version":20,"children":21,"direction":29},"root","",0,1,[22],{"type":23,"format":18,"indent":19,"version":20,"children":24,"direction":29},"paragraph",[25],{"mode":26,"text":27,"type":28,"style":18,"detail":19,"format":19,"version":20},"normal","\u003Chtml>\u003Chead>\u003C\u002Fhead>\u003Cbody>\u003Ch2>0x00 Preface\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>Previously in 'Technical Summary of Exporting All User Hashes in the Current Domain', we explored how to copy the ntds.dit file via Volume Shadow Copy to export all user hashes within the domain. Recently, I learned some new exploitation techniques from a Carbon Black blog post, which I have compiled into this article.\u003C\u002Fp>\u003Cp>\u003Cstrong>Reference link:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>https:\u002F\u002Fwww.carbonblack.com\u002F2015\u002F08\u002F05\u002Fbit9-carbon-black-threat-research-team-unveils-nefarious-intents-of-volume-shadows-copies\u002F\u003C\u002Fp>\u003Ch2>0x01 Introduction\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>This article will detail the following two aspects:\u003C\u002Fp>\u003Col>\u003Cli>Recovering files saved in system automatic restore points via Volume Shadow Copy\u003C\u002Fli>\u003Cli>Creating a fileless process via Volume Shadow Copy\u003C\u002Fli>\u003C\u002Fol>\u003Cp>The process is as follows:\u003C\u002Fp>\u003Cul>\u003Cli>Create a current volume shadow copy\u003C\u002Fli>\u003Cli>Launch programs within the shadow copy\u003C\u002Fli>\u003Cli>Delete the volume shadow copy files\u003C\u002Fli>\u003Cli>Program source files have been deleted\u003C\u002Fli>\u003Cli>This process achieves fileless execution\u003C\u002Fli>\u003C\u002Ful>\u003Ch2>0x02 Background Knowledge\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Ch3>Volume Shadow Copy Service\u003C\u002Fh3>\u003Cul>\u003Cli>Used for data backup\u003C\u002Fli>\u003Cli>Supports Windows Server 2003 and later operating systems\u003C\u002Fli>\u003Cli>The system automatically creates data backups under specific conditions by default, such as after patch installation. On Windows 7 systems, backups are automatically created approximately every week, though this timing is not guaranteed\u003C\u002Fli>\u003Cli>Disabling VSS will affect normal system functions, such as System Restore and Windows Server Backup\u003C\u002Fli>\u003Cli>VShadow can be used to manually create volume shadow copies via the command line\u003C\u002Fli>\u003Cli>VShadow is not supported by default in the system; this tool can be obtained from the Microsoft Windows Software Development Kit (SDK)\u003C\u002Fli>\u003C\u002Ful>\u003Cp>\u003Cstrong>Note:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>Windows Server 2003 and XP systems require the Volume Shadow Copy Service SDK 7.2. Download link is as follows:\u003C\u002Fp>\u003Cp>https:\u002F\u002Fwww.microsoft.com\u002Fen-us\u002Fdownload\u002Fdetails.aspx?id=23490\u003C\u002Fp>\u003Cp>Windows Server 2008 R2 and Windows 7 systems require the corresponding SDK version (this version is also applicable to Windows 8). Download link is as follows:\u003C\u002Fp>\u003Cp>https:\u002F\u002Fwww.microsoft.com\u002Fen-us\u002Fdownload\u002Fdetails.aspx?id=3138\u003C\u002Fp>\u003Ch2>0x03 Restore files saved in system automatic restore points\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Ch3>Common Commands\u003C\u002Fh3>\u003Cp>View volume shadow copies via vssadmin:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>vssadmin list shadows\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>\u003Cstrong>Note:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>vssadmin is built into the system\u003C\u002Fp>\u003Cp>As shown in the figure\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fuploads\u002Fdocx_image_1770015143152_0_63888007ce.png\">\u003C\u002Fp>\u003Cp>View volume shadow copies via wmic:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>wmic \u002FNAMESPACE:\"\\\\root\\CIMV2\" PATH Win32_ShadowCopy GET \u002Fall \u002FFORMAT:list\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>As shown in the figure\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fuploads\u002Fdocx_image_1770015146659_1_4a8528e7b7.png\">\u003C\u002Fp>\u003Cp>Extract key information: DeviceObject, ID, and InstallDate. The corresponding wmic command is:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>wmic \u002FNAMESPACE:\"\\\\root\\CIMV2\" PATH Win32_ShadowCopy GET DeviceObject,ID,InstallDate \u002FFORMAT:list\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>As shown in the figure\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fuploads\u002Fdocx_image_1770015147983_2_53c48566ea.png\">\u003C\u002Fp>\u003Cp>\u003Cstrong>Note:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>When deleting a specific shadow copy, the ID of that shadow copy must be entered\u003C\u002Fp>\u003Ch3>Create symbolic link\u003C\u002Fh3>\u003Cp>Establish a virtual association between the shadow copy and a folder, similar to accessing files saved in the shadow copy via a shortcut. Use the mklink command, which is built into the system and requires administrator privileges\u003C\u002Fp>\u003Cp>Format is as follows:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>mklink \u002Fd Specify the shortcut path [Shadow copy device name]\\\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>\u003Cstrong>Note:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>A \\ must be appended after [Shadow copy device name]\u003C\u002Fp>\u003Cp>If the \\ is accidentally omitted, subsequent operations cannot be performed after establishing the association. You can directly delete the association and recreate it\u003C\u002Fp>\u003Cp>For example, selecting \\\\?\\GLOBALROOT\\Device\\HarddiskVolumeShadowCopy4, the corresponding command is as follows:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>mklink \u002Fd c:\\testvsc \\\\?\\GLOBALROOT\\Device\\HarddiskVolumeShadowCopy4\\\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>As shown in the figure, successfully created\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fuploads\u002Fdocx_image_1770015149597_3_8a05d07f74.png\">\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fuploads\u002Fdocx_image_1770015150596_4_81f3fda6e3.jpeg\">\u003C\u002Fp>\u003Cp>The time point corresponding to \\\\?\\GLOBALROOT\\Device\\HarddiskVolumeShadowCopy4 is InstallDate=20160907160419.347805+480, thus the files saved in c:\\testvsc are those stored in the system at this time point.\u003C\u002Fp>\u003Ch2>0x04 Create a fileless process\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>Test system: Win 8.1 x86\u003C\u002Fp>\u003Cp>Test exe: Win32Project1.exe\u003C\u002Fp>\u003Cp>After execution, a dialog box pops up, as shown in the figure\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fuploads\u002Fdocx_image_1770015151862_5_7bb5283110.png\">\u003C\u002Fp>\u003Ch3>1. Create a volume shadow copy\u003C\u002Fh3>\u003Cp>Upload Win32Project1.exe and VShadow.exe, create a volume shadow copy for the current system, and execute the following command with administrator privileges:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>vshadow.exe -p c:\\\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>As shown in the figure, create a volume shadow copy for the C drive, with DeviceName as \\\\?\\GLOBALROOT\\Device\\HarddiskVolumeShadowCopy5 and ID as {10f63e0b-e47d-4121-969f-87fa458c5043}\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fuploads\u002Fdocx_image_1770015152458_6_2579e762d2.png\">\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fuploads\u002Fdocx_image_1770015153765_7_5e0c3d333b.jpeg\">\u003C\u002Fp>\u003Ch3>2. Create symbolic link\u003C\u002Fh3>\u003Cp>Execute command line:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>mklink \u002Fd c:\\vscfiletest \\\\?\\GLOBALROOT\\Device\\HarddiskVolumeShadowCopy5\\\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>Create folder c:\\vscfiletest, execute the test file Win32Project1.exe inside it\u003C\u002Fp>\u003Cp>As shown in figure\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fuploads\u002Fdocx_image_1770015154760_8_c153308ee9.jpeg\">\u003C\u002Fp>\u003Cp>Use Process Explorer to view Win32Project1.exe, the path displays as c:\\vscfiletest\\test\\Win32Project1.exe\u003C\u002Fp>\u003Cp>As shown in figure\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fuploads\u002Fdocx_image_1770015155532_9_8f8b03e25e.jpeg\">\u003C\u002Fp>\u003Ch3>3. Delete symbolic link\u003C\u002Fh3>\u003Cp>Simply delete the shortcut folder, command line parameters as follows:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>rmdir c:\\vscfiletest\\\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>\u003Cstrong>Note:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>Even if Win32Project1.exe in the folder is running, it can still be deleted\u003C\u002Fp>\u003Ch3>4. Delete volume shadow copy\u003C\u002Fh3>\u003Cp>Find the ID corresponding to the shadow copy via wmic:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>wmic \u002FNAMESPACE:\"\\\\root\\CIMV2\" PATH Win32_ShadowCopy GET DeviceObject,ID,InstallDate \u002FFORMAT:list\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>The ID corresponding to \\\\?\\GLOBALROOT\\Device\\HarddiskVolumeShadowCopy5\\ is {10f63e0b-e47d-4121-969f-87fa458c5043}\u003C\u002Fp>\u003Cp>The complete deletion command is:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>vssadmin delete shadows \u002Fshadow={10f63e0b-e47d-4121-969f-87fa458c5043} \u002Fquiet\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>\u003Cstrong>Note:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>\u002Fquiet is added to force deletion, skipping the 'Y' confirmation prompt\u003C\u002Fp>\u003Cp>As shown in the figure\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fuploads\u002Fdocx_image_1770015156274_10_b28582a563.jpeg\">\u003C\u002Fp>\u003Cp>\u003Cstrong>Additional note:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>The command to delete all shadow copies is:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>vssadmin delete shadows \u002Fall \u002Fquiet\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>At this point, Win32Project1.exe is still running in the background, while the source file c:\\vscfiletest\\test\\Win32Project1.exe no longer exists\u003C\u002Fp>\u003Cp>As shown in the figure\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fuploads\u002Fdocx_image_1770015156971_11_80cbc95092.jpeg\">\u003C\u002Fp>\u003Ch2>0x05 Defense\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cul>\u003Cli>The prerequisite for utilizing Volume Shadow Copy is obtaining administrator privileges, so the first step is to prevent attackers from gaining administrator access.\u003C\u002Fli>\u003Cli>For individual user hosts, it is recommended to directly disable the Volume Shadow Copy service.\u003C\u002Fli>\u003Cli>The defense methods provided on Carbon Black's blog are as follows:\u003C\u002Fli>\u003C\u002Ful>\u003Cp>Search by hashes:\u003C\u002Fp>\u003Cp>process_md5:3e1360a23ea5f9caf4987ccf35f2fcaf OR\u003C\u002Fp>\u003Cp>process_md5:576b379a59d094fb7b06c261a96034a6 OR\u003C\u002Fp>\u003Cp>process_md5:d0cd7ad91b2ff568275d497214ff185c OR\u003C\u002Fp>\u003Cp>process_md5:97fd0f3c05f1707544a9a6a0c896b43e OR\u003C\u002Fp>\u003Cp>process_md5:d560c155b68121d98f8370e7deafbc4d OR\u003C\u002Fp>\u003Cp>process_md5:c5d2992c8cba0771f71fe4d7625a0b8b OR\u003C\u002Fp>\u003Cp>process_md5:53d3e33ad31af6716559f29e889aca49\u003C\u002Fp>\u003Cp>Search for Vshadow being executed:\u003C\u002Fp>\u003Cp>modload:vss_ps.dll cmdline:\"-p C:\\\"\u003C\u002Fp>\u003Cp>modload:vss_ps.dll cmdline:\"-p\" -path:System32\\werfault.exe\u003C\u002Fp>\u003Cp>Search for mklink being executed via a shell out:\u003C\u002Fp>\u003Cp>cmdline:\"C:\\Windows\\system32\\cmd.exe\" \u002Fc mklink \u002FD\u003C\u002Fp>\u003Cp>Search for processes being executed from the volume shadow copy\u003C\u002Fp>\u003Cp>locations:\u003C\u002Fp>\u003Cp>path:device\u002Fharddiskvolumeshadowcopy*\u003C\u002Fp>\u003Cp>path:device\u002Fharddiskvolume*\u003C\u002Fp>\u003Cp>The above is quoted from https:\u002F\u002Fwww.carbonblack.com\u002F2015\u002F08\u002F05\u002Fbit9-carbon-black-threat-research-team-unveils-nefarious-intents-of-volume-shadows-copies\u002F\u003C\u002Fp>\u003Ch2>0x06 Summary\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>Summarizing the role of Volume Shadow Copy in penetration testing:\u003C\u002Fp>\u003Col>\u003Cli>Restore files saved in system automatic restore points via Volume Shadow Copy\u003C\u002Fli>\u003Cli>Create a fileless process via Volume Shadow Copy\u003C\u002Fli>\u003Cli>Copy files occupied by programs, such as ntds.dit. The PowerShell version of NinjaCopy can also achieve the same functionality, refer to an open-source project\u003C\u002Fli>\u003C\u002Fol>\u003Cp>\u003Cstrong>More learning materials:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>https:\u002F\u002Fwww.carbonblack.com\u002F2015\u002F08\u002F03\u002Fnew-crypto-ransomware-lurks-in-the-shadows\u002F\u003C\u002Fp>\u003Cp>http:\u002F\u002Fsecurityweekly.com\u002F2012\u002F10\u002F15\u002Fvolume-shadow-copies-the-los\u002F\u003C\u002Fp>\u003Cp>https:\u002F\u002Ftechnet.microsoft.com\u002Fen-us\u002Flibrary\u002Fee923636.aspx\u003C\u002Fp>\u003C\u002Fbody>\u003C\u002Fhtml>","text","ltr","\u003Chtml>\u003Chead>\u003C\u002Fhead>\u003Cbody>\u003Ch2>0x00 Preface\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>Previously in 'Technical Summary of Exporting All User Hashes in the Current Domain', we explored how to copy the ntds.dit file via Volume Shadow Copy to export all user hashes within the domain. Recently, I learned some new exploitation techniques from a Carbon Black blog post, which I have compiled into this article.\u003C\u002Fp>\u003Cp>\u003Cstrong>Reference link:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>https:\u002F\u002Fwww.carbonblack.com\u002F2015\u002F08\u002F05\u002Fbit9-carbon-black-threat-research-team-unveils-nefarious-intents-of-volume-shadows-copies\u002F\u003C\u002Fp>\u003Ch2>0x01 Introduction\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>This article will detail the following two aspects:\u003C\u002Fp>\u003Col>\u003Cli>Recovering files saved in system automatic restore points via Volume Shadow Copy\u003C\u002Fli>\u003Cli>Creating a fileless process via Volume Shadow Copy\u003C\u002Fli>\u003C\u002Fol>\u003Cp>The process is as follows:\u003C\u002Fp>\u003Cul>\u003Cli>Create a current volume shadow copy\u003C\u002Fli>\u003Cli>Launch programs within the shadow copy\u003C\u002Fli>\u003Cli>Delete the volume shadow copy files\u003C\u002Fli>\u003Cli>Program source files have been deleted\u003C\u002Fli>\u003Cli>This process achieves fileless execution\u003C\u002Fli>\u003C\u002Ful>\u003Ch2>0x02 Background Knowledge\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Ch3>Volume Shadow Copy Service\u003C\u002Fh3>\u003Cul>\u003Cli>Used for data backup\u003C\u002Fli>\u003Cli>Supports Windows Server 2003 and later operating systems\u003C\u002Fli>\u003Cli>The system automatically creates data backups under specific conditions by default, such as after patch installation. On Windows 7 systems, backups are automatically created approximately every week, though this timing is not guaranteed\u003C\u002Fli>\u003Cli>Disabling VSS will affect normal system functions, such as System Restore and Windows Server Backup\u003C\u002Fli>\u003Cli>VShadow can be used to manually create volume shadow copies via the command line\u003C\u002Fli>\u003Cli>VShadow is not supported by default in the system; this tool can be obtained from the Microsoft Windows Software Development Kit (SDK)\u003C\u002Fli>\u003C\u002Ful>\u003Cp>\u003Cstrong>Note:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>Windows Server 2003 and XP systems require the Volume Shadow Copy Service SDK 7.2. Download link is as follows:\u003C\u002Fp>\u003Cp>https:\u002F\u002Fwww.microsoft.com\u002Fen-us\u002Fdownload\u002Fdetails.aspx?id=23490\u003C\u002Fp>\u003Cp>Windows Server 2008 R2 and Windows 7 systems require the corresponding SDK version (this version is also applicable to Windows 8). Download link is as follows:\u003C\u002Fp>\u003Cp>https:\u002F\u002Fwww.microsoft.com\u002Fen-us\u002Fdownload\u002Fdetails.aspx?id=3138\u003C\u002Fp>\u003Ch2>0x03 Restore files saved in system automatic restore points\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Ch3>Common Commands\u003C\u002Fh3>\u003Cp>View volume shadow copies via vssadmin:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>vssadmin list shadows\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>\u003Cstrong>Note:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>vssadmin is built into the system\u003C\u002Fp>\u003Cp>As shown in the figure\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fapi\u002Fmedia\u002Ffile\u002Fdocx_image_1770015143152_0_63888007ce-1.png\">\u003C\u002Fp>\u003Cp>View volume shadow copies via wmic:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>wmic \u002FNAMESPACE:\"\\\\root\\CIMV2\" PATH Win32_ShadowCopy GET \u002Fall \u002FFORMAT:list\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>As shown in the figure\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fapi\u002Fmedia\u002Ffile\u002Fdocx_image_1770015146659_1_4a8528e7b7-1.png\">\u003C\u002Fp>\u003Cp>Extract key information: DeviceObject, ID, and InstallDate. The corresponding wmic command is:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>wmic \u002FNAMESPACE:\"\\\\root\\CIMV2\" PATH Win32_ShadowCopy GET DeviceObject,ID,InstallDate \u002FFORMAT:list\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>As shown in the figure\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fapi\u002Fmedia\u002Ffile\u002Fdocx_image_1770015147983_2_53c48566ea-1.png\">\u003C\u002Fp>\u003Cp>\u003Cstrong>Note:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>When deleting a specific shadow copy, the ID of that shadow copy must be entered\u003C\u002Fp>\u003Ch3>Create symbolic link\u003C\u002Fh3>\u003Cp>Establish a virtual association between the shadow copy and a folder, similar to accessing files saved in the shadow copy via a shortcut. Use the mklink command, which is built into the system and requires administrator privileges\u003C\u002Fp>\u003Cp>Format is as follows:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>mklink \u002Fd Specify the shortcut path [Shadow copy device name]\\\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>\u003Cstrong>Note:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>A \\ must be appended after [Shadow copy device name]\u003C\u002Fp>\u003Cp>If the \\ is accidentally omitted, subsequent operations cannot be performed after establishing the association. You can directly delete the association and recreate it\u003C\u002Fp>\u003Cp>For example, selecting \\\\?\\GLOBALROOT\\Device\\HarddiskVolumeShadowCopy4, the corresponding command is as follows:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>mklink \u002Fd c:\\testvsc \\\\?\\GLOBALROOT\\Device\\HarddiskVolumeShadowCopy4\\\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>As shown in the figure, successfully created\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fapi\u002Fmedia\u002Ffile\u002Fdocx_image_1770015149597_3_8a05d07f74-1.png\">\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fapi\u002Fmedia\u002Ffile\u002Fdocx_image_1770015150596_4_81f3fda6e3-1.jpeg\">\u003C\u002Fp>\u003Cp>The time point corresponding to \\\\?\\GLOBALROOT\\Device\\HarddiskVolumeShadowCopy4 is InstallDate=20160907160419.347805+480, thus the files saved in c:\\testvsc are those stored in the system at this time point.\u003C\u002Fp>\u003Ch2>0x04 Create a fileless process\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>Test system: Win 8.1 x86\u003C\u002Fp>\u003Cp>Test exe: Win32Project1.exe\u003C\u002Fp>\u003Cp>After execution, a dialog box pops up, as shown in the figure\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fapi\u002Fmedia\u002Ffile\u002Fdocx_image_1770015151862_5_7bb5283110-1.png\">\u003C\u002Fp>\u003Ch3>1. Create a volume shadow copy\u003C\u002Fh3>\u003Cp>Upload Win32Project1.exe and VShadow.exe, create a volume shadow copy for the current system, and execute the following command with administrator privileges:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>vshadow.exe -p c:\\\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>As shown in the figure, create a volume shadow copy for the C drive, with DeviceName as \\\\?\\GLOBALROOT\\Device\\HarddiskVolumeShadowCopy5 and ID as {10f63e0b-e47d-4121-969f-87fa458c5043}\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fapi\u002Fmedia\u002Ffile\u002Fdocx_image_1770015152458_6_2579e762d2-1.png\">\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fapi\u002Fmedia\u002Ffile\u002Fdocx_image_1770015153765_7_5e0c3d333b-1.jpeg\">\u003C\u002Fp>\u003Ch3>2. Create symbolic link\u003C\u002Fh3>\u003Cp>Execute command line:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>mklink \u002Fd c:\\vscfiletest \\\\?\\GLOBALROOT\\Device\\HarddiskVolumeShadowCopy5\\\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>Create folder c:\\vscfiletest, execute the test file Win32Project1.exe inside it\u003C\u002Fp>\u003Cp>As shown in figure\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fapi\u002Fmedia\u002Ffile\u002Fdocx_image_1770015154760_8_c153308ee9-1.jpeg\">\u003C\u002Fp>\u003Cp>Use Process Explorer to view Win32Project1.exe, the path displays as c:\\vscfiletest\\test\\Win32Project1.exe\u003C\u002Fp>\u003Cp>As shown in figure\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fapi\u002Fmedia\u002Ffile\u002Fdocx_image_1770015155532_9_8f8b03e25e-1.jpeg\">\u003C\u002Fp>\u003Ch3>3. Delete symbolic link\u003C\u002Fh3>\u003Cp>Simply delete the shortcut folder, command line parameters as follows:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>rmdir c:\\vscfiletest\\\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>\u003Cstrong>Note:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>Even if Win32Project1.exe in the folder is running, it can still be deleted\u003C\u002Fp>\u003Ch3>4. Delete volume shadow copy\u003C\u002Fh3>\u003Cp>Find the ID corresponding to the shadow copy via wmic:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>wmic \u002FNAMESPACE:\"\\\\root\\CIMV2\" PATH Win32_ShadowCopy GET DeviceObject,ID,InstallDate \u002FFORMAT:list\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>The ID corresponding to \\\\?\\GLOBALROOT\\Device\\HarddiskVolumeShadowCopy5\\ is {10f63e0b-e47d-4121-969f-87fa458c5043}\u003C\u002Fp>\u003Cp>The complete deletion command is:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>vssadmin delete shadows \u002Fshadow={10f63e0b-e47d-4121-969f-87fa458c5043} \u002Fquiet\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>\u003Cstrong>Note:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>\u002Fquiet is added to force deletion, skipping the 'Y' confirmation prompt\u003C\u002Fp>\u003Cp>As shown in the figure\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fapi\u002Fmedia\u002Ffile\u002Fdocx_image_1770015156274_10_b28582a563-1.jpeg\">\u003C\u002Fp>\u003Cp>\u003Cstrong>Additional note:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>The command to delete all shadow copies is:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>vssadmin delete shadows \u002Fall \u002Fquiet\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>At this point, Win32Project1.exe is still running in the background, while the source file c:\\vscfiletest\\test\\Win32Project1.exe no longer exists\u003C\u002Fp>\u003Cp>As shown in the figure\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fapi\u002Fmedia\u002Ffile\u002Fdocx_image_1770015156971_11_80cbc95092-1.jpeg\">\u003C\u002Fp>\u003Ch2>0x05 Defense\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cul>\u003Cli>The prerequisite for utilizing Volume Shadow Copy is obtaining administrator privileges, so the first step is to prevent attackers from gaining administrator access.\u003C\u002Fli>\u003Cli>For individual user hosts, it is recommended to directly disable the Volume Shadow Copy service.\u003C\u002Fli>\u003Cli>The defense methods provided on Carbon Black's blog are as follows:\u003C\u002Fli>\u003C\u002Ful>\u003Cp>Search by hashes:\u003C\u002Fp>\u003Cp>process_md5:3e1360a23ea5f9caf4987ccf35f2fcaf OR\u003C\u002Fp>\u003Cp>process_md5:576b379a59d094fb7b06c261a96034a6 OR\u003C\u002Fp>\u003Cp>process_md5:d0cd7ad91b2ff568275d497214ff185c OR\u003C\u002Fp>\u003Cp>process_md5:97fd0f3c05f1707544a9a6a0c896b43e OR\u003C\u002Fp>\u003Cp>process_md5:d560c155b68121d98f8370e7deafbc4d OR\u003C\u002Fp>\u003Cp>process_md5:c5d2992c8cba0771f71fe4d7625a0b8b OR\u003C\u002Fp>\u003Cp>process_md5:53d3e33ad31af6716559f29e889aca49\u003C\u002Fp>\u003Cp>Search for Vshadow being executed:\u003C\u002Fp>\u003Cp>modload:vss_ps.dll cmdline:\"-p C:\\\"\u003C\u002Fp>\u003Cp>modload:vss_ps.dll cmdline:\"-p\" -path:System32\\werfault.exe\u003C\u002Fp>\u003Cp>Search for mklink being executed via a shell out:\u003C\u002Fp>\u003Cp>cmdline:\"C:\\Windows\\system32\\cmd.exe\" \u002Fc mklink \u002FD\u003C\u002Fp>\u003Cp>Search for processes being executed from the volume shadow copy\u003C\u002Fp>\u003Cp>locations:\u003C\u002Fp>\u003Cp>path:device\u002Fharddiskvolumeshadowcopy*\u003C\u002Fp>\u003Cp>path:device\u002Fharddiskvolume*\u003C\u002Fp>\u003Cp>The above is quoted from https:\u002F\u002Fwww.carbonblack.com\u002F2015\u002F08\u002F05\u002Fbit9-carbon-black-threat-research-team-unveils-nefarious-intents-of-volume-shadows-copies\u002F\u003C\u002Fp>\u003Ch2>0x06 Summary\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>Summarizing the role of Volume Shadow Copy in penetration testing:\u003C\u002Fp>\u003Col>\u003Cli>Restore files saved in system automatic restore points via Volume Shadow Copy\u003C\u002Fli>\u003Cli>Create a fileless process via Volume Shadow Copy\u003C\u002Fli>\u003Cli>Copy files occupied by programs, such as ntds.dit. The PowerShell version of NinjaCopy can also achieve the same functionality, refer to an open-source project\u003C\u002Fli>\u003C\u002Fol>\u003Cp>\u003Cstrong>More learning materials:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>https:\u002F\u002Fwww.carbonblack.com\u002F2015\u002F08\u002F03\u002Fnew-crypto-ransomware-lurks-in-the-shadows\u002F\u003C\u002Fp>\u003Cp>http:\u002F\u002Fsecurityweekly.com\u002F2012\u002F10\u002F15\u002Fvolume-shadow-copies-the-los\u002F\u003C\u002Fp>\u003Cp>https:\u002F\u002Ftechnet.microsoft.com\u002Fen-us\u002Flibrary\u002Fee923636.aspx\u003C\u002Fp>\u003C\u002Fbody>\u003C\u002Fhtml>",389,"Onedaysec",5,"published","2026-02-02T07:25:19.985Z",{"title":37,"description":14,"keywords":38,"ogImage":39,"canonicalUrl":39,"noIndex":40},"Volume Shadow Copy Exploitation in Penetration Testing","Volume Shadow Copy, penetration testing, fileless process, VSS exploitation, Windows security, shadow copy, vssadmin, wmic, mklink, data recovery",null,false,[],{"docs":43,"hasNextPage":40},[4,44,45,46],1027,1026,1025,{"title":39,"description":39,"image":39},"2026-07-24T15:37:10.129Z","2026-07-23T16:02:26.736Z","draft","2026-07-23T16:16:13.031Z"]