Skip to content

New Query: SMB File Copy to Multiple Devices (Microsoft Defender for Identity)#54

Merged
dweissbacher merged 1 commit into
mainfrom
submission/dcc289b7-c928-4c7a-ab57-518ddf9be972
May 21, 2026
Merged

New Query: SMB File Copy to Multiple Devices (Microsoft Defender for Identity)#54
dweissbacher merged 1 commit into
mainfrom
submission/dcc289b7-c928-4c7a-ab57-518ddf9be972

Conversation

@byteray-cql-hub-bot
Copy link
Copy Markdown
Contributor

New Query Submission

Name: SMB File Copy to Multiple Devices (Microsoft Defender for Identity)
Author: Kundan Kumar
Submission ID: dcc289b7-c928-4c7a-ab57-518ddf9be972

Description

Detects instances where files are copied over SMB to multiple devices within a short timeframe, as identified by Microsoft Defender for Identity. This behavior may indicate lateral movement where an attacker distributes tools or payloads across systems to expand access and establish control.


This PR was automatically created by the CQL Hub submission pipeline.

@dweissbacher dweissbacher merged commit 4e24be1 into main May 21, 2026
2 checks passed
@dweissbacher dweissbacher deleted the submission/dcc289b7-c928-4c7a-ab57-518ddf9be972 branch May 21, 2026 11:01
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant