It may be performed by an external attacker, a malicious or careless insider, compromised software, or an abused third-party connection.
Exfiltration can be fast and obvious or divided into small transfers that blend into ordinary activity. Channels include cloud storage, email, web uploads, messaging, remote administration tools, DNS, encrypted tunnels, removable media, printing, and photographs. Investigation should determine what data was transferred, which account, process, device, and path were involved, who or what received it, and whether the transfer succeeded.
Key points
PreventionLeast privilege, data classification, segmentation, controlled egress, DLP, secure collaboration, and well-governed third-party access.
DetectionEndpoint, identity, network, cloud, application, and data-access telemetry examined in business context.
ResponsePreserve evidence, contain the path, protect affected identities, assess the data and recipients, and meet notification duties.
Important limitationA large transfer is not necessarily malicious, while a small transfer may contain the organization’s most sensitive information.