robocopy.exe

by Microsoft
System Utilitymedium risk

Summary

Robust File Copy. Windows built-in for high-performance file copying with resume, mirroring, and multi-threaded support. Used by attackers for data staging and collection — can efficiently copy large volumes of files for exfiltration.

robocopy.exe is the 1709th most commonly executed Windows program in EchoTrail's dataset, observed 481 times across enterprise environments. It typically runs from C:\Windows\SysWOW64 and it is most often launched by cmd.exe.

1709th
most commonly executed Windows program
481
observed executions
low
statistical confidence

Behavior

Top Paths

  • C:\Windows\SysWOW6484.62%
  • C:\Windows\System3215.38%

Top Hashes (SHA256)

  • 34ef7ddc25ad476fe1afc29fa6a961dcdfcb1cc3bf1fbb14162d16aafe3b21d228.88%
  • 83428f8fd1cf608e162db16666509666c1982713ae813f781c9de3cd23e0fc1114.66%
  • d7a46fc5af4dc3978f395dd601619111899d206c22aabdac77c10efe6a8425a98.53%
  • b5a99113cc15c20ec50f2e2042a06c7760ee79504c559d8368334923f6be1eb77.22%
  • d1affe6cd79f9d755548757198b37091d9c898fe35289b92b5cf833cae02dadf6.13%
  • f3da41972f2aca2138be2c475786911d837020ffc406b45d9a3e0907898b06cb5.91%
  • f879c52c110afaa8e67a4b2c180cbfb48bcf52fa0dbeac0d26b1474e897679ad5.91%
  • f794eec15010239d23182299cedbf75735e01ccbd417fb81be0dc02118eb829f5.25%
  • af762961e3d47c8e378e1b5127e3a3f1000d5382088d234aee9553ec2e30e2914.6%
  • 671f803f9ae47e7ae6aa0de1e76b1a23ceb6133cfd9d7a9bfd6a12521443168c3.28%

Process Ancestry

Top Grandparents

Top Parents

Rare or environment-specific process names are omitted from ancestry tables. Percentages are of all observed relationships.

Security Analysis

What does robocopy.exe normally do?

Runs from C:\Windows\System32. Used by IT for file migrations, backups, and directory synchronization. Common in scripts and scheduled tasks for data management.

When is robocopy.exe suspicious?

Copying files to removable media or network shares outside normal backup patterns. Targeting sensitive directories (finance, HR, executive folders). Large-volume copies at unusual times. Copying specific file types (.doc, .xls, .pdf, .pst) suggesting targeted collection.

How do attackers abuse robocopy.exe?

DATA STAGING: Attackers use robocopy to collect and stage data before exfiltration: - "robocopy \\server\share C:\staging /S /E" — mirror a file share for exfiltration - "robocopy C:\Users\exec C:\staging *.doc *.xls *.pdf /S" — collect documents - Multi-threaded (/MT) flag for rapid collection Robocopy's resume capability makes it useful for large-scale data theft. Its legitimate prevalence provides cover.

Detection guidance

MEDIUM-CONFIDENCE: - robocopy targeting file shares with sensitive data - robocopy copying to removable media paths - robocopy with file type filters targeting documents (.doc, .xls, .pdf, .pst) - Large robocopy operations at unusual hours - robocopy run by non-admin users against network shares DATA SOURCES: Process creation with command line (Sysmon 1), file access events

False positive notes

Extremely common in IT operations. Backup scripts, file migrations, user profile migrations, and directory synchronization all use robocopy. Context matters more than execution alone.

MITRE ATT&CK techniques

References

Related Processes

Ask Rocky about robocopy.exe

Rocky answers questions about robocopy.exe grounded in this same dataset — free, no account needed.

Need this data programmatically? The Rocky API includes 500 free lookups a month. Or just ask Rocky.

Data from EchoTrail's dataset of ~346M Windows process executions. Last extracted 2026-08-04.