Skip to content

New Query: High Volume SMB File Copy (Data Exfiltration / Ransomware) – Microsoft Defender for Identity#55

Merged
dweissbacher merged 1 commit into
mainfrom
submission/f015cfd7-ee64-430a-9b9c-d8d71c2718df
May 21, 2026
Merged

New Query: High Volume SMB File Copy (Data Exfiltration / Ransomware) – Microsoft Defender for Identity#55
dweissbacher merged 1 commit into
mainfrom
submission/f015cfd7-ee64-430a-9b9c-d8d71c2718df

Conversation

@byteray-cql-hub-bot
Copy link
Copy Markdown
Contributor

New Query Submission

Name: High Volume SMB File Copy (Data Exfiltration / Ransomware) – Microsoft Defender for Identity
Author: Kundan Kumar
Submission ID: f015cfd7-ee64-430a-9b9c-d8d71c2718df

Description

Detects a large volume of file transfers over SMB within a short timeframe, as identified by Microsoft Defender for Identity. This behavior may indicate bulk data exfiltration or ransomware activity, where files are rapidly copied, staged, or encrypted across systems and should be investigated immediately.


This PR was automatically created by the CQL Hub submission pipeline.

@dweissbacher dweissbacher merged commit 894b0f5 into main May 21, 2026
2 checks passed
@dweissbacher dweissbacher deleted the submission/f015cfd7-ee64-430a-9b9c-d8d71c2718df branch May 21, 2026 11:19
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant