-
AzCopy or Azure Storage Explorer Usage on Unusual Host
Sep 10, 2026 · Domain: Endpoint OS: Windows Platform: Windows Use Case: Threat Detection Tactic: Exfiltration Tactic: Collection Tactic: Execution Rule Type: New Terms Threat: Rhysida Use Case: Ransomware Resources: Investigation Guide Data Source: Elastic Defend Data Source: Sysmon Data Source: Microsoft Defender XDR Data Source: Crowdstrike ·Identifies the first time, in a historical window, a host runs AzCopy copy or sync to Azure Blob, Data Lake, or File storage, or starts Azure Storage Explorer. These Microsoft utilities are legitimate data-transfer tools; ransomware and cloud-ransomware operators drop portable copies and use SAS-authenticated jobs to pull data from victim storage and push it to attacker-controlled accounts.
Read More