xcopy.exe

by Microsoft
System Utilitymedium risk

Sources: 300M+ executions observed in the wild.

Summary

Windows Extended Copy utility - copies files and directory trees with more options than the basic copy command.

xcopy.exe is the 806th most commonly executed Windows program in EchoTrail's dataset, observed 3,846 times across enterprise environments. It typically runs from C:\Windows\System32 and it is most often launched by cmd.exe.

Get this in your tools

The same record for xcopy.exe, by REST or as an MCP tool. Free key, no card.

Get a free key
curl -H "Authorization: Bearer $ECHOTRAIL_KEY" \
  https://api.echotrail.io/v1/process/xcopy.exe

Free returns the summary. Team returns the full record you see on this page. Endpoint docs

806th
most commonly executed Windows program
3,846
observed endpoint executions

Behavior

Top Paths

  • C:\Windows\System3283.81%
  • C:\Windows\SysWOW6416.19%

Top Hashes (SHA256)

  • 269eb0728413654856f4b2ee1fa7838cd69672ebc11baed4caa63f58c2df582379.1%
  • 822c4e9f406b7544ba68083b03c83e79a38d57848f5549a560c5205ed0f2cfab5.99%
  • 090ed2bd2623f57047f80711ce4a8ec2329e5c4e22316f992663fafc17cf1f3f4.07%
  • a09f04fc2c4208827f6b817b85e13d3844c76d4f9dda7a9e76030a0ccf6e594f3.1%
  • 6bb3fbaa37e680269d90ab7448d8a2cb578510b6e179dff9d46f721deb06097d1.43%
  • dc5484e676ff14937d004b8c1895f0c3ef8b4d8b28589de8b77aee1f518d9a211.38%
  • 309bad3c84c4830b6c71f8212a0cb13a44cc119bb4ebec57dfba0625ccdaec260.89%
  • ebf89c15d0ce966b3bd6aa726e7db80fc545bac521c3ab99ef1d5942ed02528c0.86%
  • 6f5ff1af741bdcaf2caeef27a922480271211ce8081a2aa73d7cbd0de2fa2fb20.83%
  • adb4a07a567002816658087b3e053e1a1b847be0216be0627f2302f55fe2c63f0.83%

Process Ancestry

Top Grandparents

Top Parents

Top Children

Security Analysis

What does xcopy.exe normally do?

Used in batch scripts for file copy operations, backup scripts, and deployment workflows.

When is xcopy.exe suspicious?

Copying files to network shares or removable media. Copying sensitive directories (user profiles, email stores, database files). Large-volume copy operations on endpoints.

How do attackers abuse xcopy.exe?

Attackers use xcopy for data staging before exfiltration and for lateral file transfer via network shares. The /h flag copies hidden and system files. Can be used to copy SAM database files.

Detection guidance

Monitor xcopy destinations, especially network paths and removable drives. Alert on copying from sensitive directories.

False positive notes

Backup scripts, deployment tools, and migration utilities commonly use xcopy.

MITRE ATT&CK techniques

Related Processes

Ask Rocky about xcopy.exe

Rocky is the free chat demo. It answers from this same dataset, no account needed.

This page is the Team-tier API record for xcopy.exe. The free tier returns the summary, 500 lookups a month. Or ask Rocky.