Sponsored by Hudson Rock Use Hudson Rock's free cybercrime intelligence tools to learn how Infostealer infections are leading to ransomware attacks

INC Ransom – Restic / s5cmd Invoked for Covert Cloud Exfiltration

Incransom Exfiltration Sentinel
MITRE ATT&CK
Exfiltration to Cloud Storage
Data Source
DeviceProcessEvents
Date Added
2026-07-23
Last Updated
2026-07-23
Source
ransomware.live group_tools dataset (incransom)
What This Detects
INC Ransom favors the Restic backup utility and s5cmd over more common exfil tools like RClone – an uncommon-enough combination on endpoints to be high-signal. Flags either tool invoked with backup/upload flags.
Query
DeviceProcessEvents
| where Timestamp > ago(1d)
| where FileName in~ ("restic.exe","s5cmd.exe")
| where ProcessCommandLine has_any ("backup","cp","b2","backblaze","s3://")
| project Timestamp, DeviceName, FileName, ProcessCommandLine, AccountName, FolderPath

Hunting queries are starting points for threat hunting & detection engineering — validate table/column names against your own workspace schema and tune thresholds before turning any of these into a production alert rule.