Knowledge / detection IR network

Exfiltration

Data leaving. Bulk, slow, or stuffed into a protocol nobody is watching. DLP is a control; logs are how you know.

Exfiltration is taking data out: cloud upload, email, DNS, HTTPS to a drop box, physical copy. Volume spikes are easy. Low-and-slow over an allowed path is not.

Watch egress to rare destinations, compressed or encrypted blobs where you expect documents, and channels that never carried that much before. Blocking one SaaS without logging the rest is theatre.

See also: Data loss prevention, DNS tunnelling, Network detection and response, Logging.