Vshadow.exe

VShadow is a command-line tool that can be used to create and manage volume shadow copies.

Paths

  • C:\Program Files (x86)\Windows Kits\10\bin\<version>\x64\vshadow.exe

Commands

Execute

Executes specified executable from vshadow.exe.

Use case: Performs execution of specified executable file.

Privileges: Administrator

vshadow.exe -nw -exec={PATH_ABSOLUTE:.exe} C:

Detection

Resources