Skip to content
OPS // KITitspentest.sh

E-AZC

azcopy

Microsoft's official high-performance CLI for copying data to and from Azure Blob and File storage — bulk data review or, with authorization, extraction.

Official siteInstallBack to catalog

OVERVIEW

AzCopy (github.com/Azure/azure-storage-azcopy) is Microsoft's official command-line utility for high-performance data transfer to and from Azure Blob and File storage. It is the same tool Azure administrators use for production data migrations, which makes it a natural fit once a cloud assessment has confirmed read access to a storage account or container: it can list, download, or copy the contents at production-grade speed instead of paging through the portal or the SDK by hand.

Beyond a working SAS token, storage account key, or Azure AD identity, AzCopy needs no additional setup — it authenticates the same way `az storage` does and supports the same scoped credentials, so an assessment can reuse whatever access was already provisioned. Its `azcopy list` and `azcopy copy --dry-run` modes are useful for enumerating and confirming exposure without moving any data at all.

USE CASES

Practical use cases

  • 01

    Enumerating the contents of an accessible Blob container or File share with `azcopy list` before deciding whether to pull anything.

  • 02

    Bulk-downloading sample files from an exposed container to demonstrate real data exposure in a finding, with client authorization.

  • 03

    Benchmarking how much data a compromised SAS token or storage key can actually reach, at production transfer speed.

  • 04

    Copying data between storage accounts during an authorized data-exfiltration simulation for a red team engagement.

QUICK START

Once storage access is confirmed during an Azure assessment, to bulk-review accessible blobs/files or, with explicit written authorization, copy data out as evidence.

  1. Install AzCopy (or download the static binary) and confirm the assessment has an authorized SAS token, storage key, or Azure AD identity for the target account.
  2. Run `azcopy login` if using Azure AD, or pass the SAS token directly in the resource URL for scoped access.
  3. List reachable containers and blobs first with `azcopy list` to confirm scope before copying anything.
  4. Copy only what is needed for evidence with `azcopy copy`, and log every transfer for the report.
azcopy — bash
azcopy list "https://<account>.blob.core.windows.net/<container>?<sas-token>"

BEFORE YOU RUN IT

What to check before running it

AzCopy genuinely moves and copies data — any transfer of real client data out of a storage account needs explicit written authorization, scoped to what the engagement actually requires.

Transfers are logged in Azure Storage diagnostic logs and, for AAD auth, Entra ID sign-in logs — agree with the client on expected volume and timing beforehand.

Prefer `azcopy list` or `--dry-run` to confirm exposure first; only copy the minimum needed for evidence, and delete local copies once the finding is documented.

KEEP EXPLORING

View the whole phase →