HuntCONSTRUCTEDMembers

Hunt: rclone, including when it has been renamed

Finds rclone by what the binary says about itself rather than by its file name, so a copy renamed to svchost.exe in a user folder still shows up. The commonest data theft tool in ransomware operations.

ExfiltrationT1567.002T1048checked 2026-09-26

Written for

  • KQL, Microsoft Defender XDR
  • SPL, Splunk with Sysmon
  • Elastic, EQL, Elastic Defend or Winlogbeat with Sysmon

Needs

  • Process creation with version information: Defender for Endpoint, Sysmon event 1 (OriginalFileName, Description, Company), or Elastic Defend

sources

  1. MITRE ATT&CK S1040, Rclone · primary
  2. MITRE ATT&CK T1567.002, Exfiltration to Cloud Storage
  3. Microsoft Learn: the DeviceProcessEvents table in advanced hunting

Tags: hunting · exfiltration · rclone · ransomware · sysmon · defender-xdr · splunk · elastic · T1567.002