E-AZC
azcopy
Microsoft's official high-performance CLI for copying data to and from Azure Blob and File storage — bulk data review or, with authorization, extraction.
Official siteInstallBack to catalog
OVERVIEW
AzCopy (github.com/Azure/azure-storage-azcopy) is Microsoft's official command-line utility for high-performance data transfer to and from Azure Blob and File storage. It is the same tool Azure administrators use for production data migrations, which makes it a natural fit once a cloud assessment has confirmed read access to a storage account or container: it can list, download, or copy the contents at production-grade speed instead of paging through the portal or the SDK by hand.
Beyond a working SAS token, storage account key, or Azure AD identity, AzCopy needs no additional setup — it authenticates the same way `az storage` does and supports the same scoped credentials, so an assessment can reuse whatever access was already provisioned. Its `azcopy list` and `azcopy copy --dry-run` modes are useful for enumerating and confirming exposure without moving any data at all.
USE CASES
Practical use cases
- 01
Enumerating the contents of an accessible Blob container or File share with `azcopy list` before deciding whether to pull anything.
- 02
Bulk-downloading sample files from an exposed container to demonstrate real data exposure in a finding, with client authorization.
- 03
Benchmarking how much data a compromised SAS token or storage key can actually reach, at production transfer speed.
- 04
Copying data between storage accounts during an authorized data-exfiltration simulation for a red team engagement.
QUICK START
Once storage access is confirmed during an Azure assessment, to bulk-review accessible blobs/files or, with explicit written authorization, copy data out as evidence.
- Install AzCopy (or download the static binary) and confirm the assessment has an authorized SAS token, storage key, or Azure AD identity for the target account.
- Run `azcopy login` if using Azure AD, or pass the SAS token directly in the resource URL for scoped access.
- List reachable containers and blobs first with `azcopy list` to confirm scope before copying anything.
- Copy only what is needed for evidence with `azcopy copy`, and log every transfer for the report.
azcopy list "https://<account>.blob.core.windows.net/<container>?<sas-token>"BEFORE YOU RUN IT
What to check before running it
AzCopy genuinely moves and copies data — any transfer of real client data out of a storage account needs explicit written authorization, scoped to what the engagement actually requires.
Transfers are logged in Azure Storage diagnostic logs and, for AAD auth, Entra ID sign-in logs — agree with the client on expected volume and timing beforehand.
Prefer `azcopy list` or `--dry-run` to confirm exposure first; only copy the minimum needed for evidence, and delete local copies once the finding is documented.