Skip to content

CopyBlob

Azure

CopyBlob

service: Azure - Azure Blob Storage
techniques:

Event

Copies from a source URI to the destination addressed by the request. Source and destination authorization are separate; x-ms-copy-source identifies the source. Copy Blob can complete asynchronously, so HTTP 202 does not prove the copy finished. Inspect the copy status and resulting destination object.

Security Context

Unauthorized copies may collect cloud data (T1530) or transfer it to another cloud account (T1537). Migration and backup are common. Account names and object paths do not establish external ownership, sensitive contents, or completed exfiltration.

Log Source

Azure Storage resource logs, StorageBlobLogs when routed in resource-specific mode to Log Analytics. Collect relevant Blob service diagnostic categories, including StorageWrite for this destination copy request. Resource logs require diagnostic configuration; the source account alone may not expose a destination-account event.

Key Fields

FieldInvestigation value
AccountName, Uri, DestinationUri, SourceUriDestination account/request and source where logged.
AuthenticationType, RequesterObjectId, RequesterTenantIdRecorded request identity; distinguish destination OAuth authorization from source authorization.
TenantId, _ResourceIdLog Analytics workspace ID and logged resource, respectively; TenantId here is not the Entra tenant ID.

What to Investigate

  1. Confirm the recorded outcome and compare actor, target, and timing with the approved workflow.
  2. Resolve source/destination ownership, authorizations, and diagnostic coverage for both accounts.
  3. Confirm copy ID/status and destination contents using approved evidence; a zero-byte response is not the amount copied.
  4. Correlate source reads and downstream access. Do not link an unrelated blob path to a managed-disk SAS event.

Sample Event

Synthetic scenario. The destination logs an accepted copy request for a Parquet blob. This is not the disk/snapshot export described elsewhere. The source query is omitted to avoid illustrating a usable SAS; source authorization and copy completion are not shown.

Exact field presence, modified-property names, payload nesting, and timestamp formatting remain unverified against captured logs. Names and illustrative identifiers do not prove intent or downstream activity.

{
"TimeGenerated": "2026-04-15T19:38:42.5172983Z",
"AccountName": "flcdracoexfil666",
"Category": "StorageWrite",
"OperationName": "CopyBlob",
"OperationVersion": "2024-08-04",
"ServiceType": "blob",
"StatusCode": "202",
"StatusText": "Success",
"DurationMs": 84,
"ServerLatencyMs": 78,
"RequestBodySize": 0,
"ResponseBodySize": 0,
"RequestHeaderSize": 1248,
"ResponseHeaderSize": 412,
"TlsVersion": "TLS 1.3",
"AuthenticationType": "OAuth",
"RequesterObjectId": "30000000-0000-4000-8000-001010011010",
"RequesterUpn": "draco@fantasticlogs.cloud",
"RequesterTenantId": "10000000-0000-4000-8000-000000000001",
"RequesterAppId": "04b07795-8ddb-461a-bbee-02f9e1bf7b46",
"CallerIpAddress": "203.0.113.66:54321",
"UserAgentHeader": "azsdk-python-storage-blob/12.19.0 Python/3.11.6 (Linux-5.15.0-1052-aws-x86_64-with-glibc2.35)",
"ClientRequestId": "90000000-0000-4000-8000-000001110000",
"Uri": "https://flcdracoexfil666.blob.core.windows.net/loot/customers/2026-q2/luna_lovegood.parquet?api-version=2024-08-04",
"OperationCount": 1,
"SourceUri": "https://flcoccamy001.blob.core.windows.net/customers/2026-q2/luna_lovegood.parquet",
"DestinationUri": "https://flcdracoexfil666.blob.core.windows.net/loot/customers/2026-q2/luna_lovegood.parquet",
"_ResourceId": "/subscriptions/20000000-0000-4000-8000-000000000001/resourceGroups/rg-draco-staging-666/providers/Microsoft.Storage/storageAccounts/flcdracoexfil666",
"TenantId": "70000000-0000-4000-8000-000000000001"
}

Sources

MITRE ATT&CK Mapping

Tactics: Collection Exfiltration

Techniques:
  • T1530 — Data from Cloud Storage — Adversaries may access data from cloud storage.
  • T1537 — Transfer Data to Cloud Account — Adversaries may exfiltrate data by transferring the data, including through sharing/syncing and creating backups of cloud environments, to another cloud account they control on the same service.
Documentation reviewed: October 4, 2026. Samples are synthetic illustrations, not captured production logs or lab-validated fixtures.