Suspicious Azure CLI Disk Snapshot and Copy for Data Theft

PremiumReviewedSigma · Medium · v1
Category
process_creation
Author
HuntRule
Published
2026-05-13
Updated
2026-08-28

ATT&CK techniques

Defense Evasion → Collection
  1. Recon

  2. Resource Dev

  3. Initial Access

  4. Execution

  5. Persistence

  6. Priv Esc

  7. Cred Access

  8. Discovery

  9. Lateral Movement

  10. C2

  11. Exfiltration

  12. Impact

What it detects

This rule detects Azure CLI commands that create a managed disk snapshot or clone a disk from an existing source. It maps to cloud data theft where an attacker snapshots a target VM disk and attaches a copy to an unmonitored instance to read its contents. Detecting it exposes disk exfiltration through the cloud control plane.

Related detections9 linkedT1005 — drag to rearrange
Suspicious BoryptGrab Infostealer Staging Directory (via file_event)
Suspicious Compute Disk IAM Policy Modification Granting Owner Role via GCP Audit
Suspicious Astaroth Spambot Browser Profile Staging Directory (via file_event)
Suspicious EBS Snapshot Shared With External Account via CloudTrail
Suspicious Browser and Wallet Credential Theft via JavaScript Stealer
Suspicious WhatsAppBackup Data Staging Archive Creation
Suspicious Environment File Credential Search via findstr (via process_creation)
Suspicious RDP Bitmap Cache Temp Files Written by mstsc in Rogue RDP Campaign (via file_event)
Windows Script Interpreter Launching trufflehog or gitleaks Credential Scanner
Suspicious Azure CLI Disk Snapshot and Copy for Data Theft
Pivot detection · T1005 · 9 related

Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.