M ManySignal
TA0010 ATT&CK Tactic

Exfiltration

Data exfiltration is the moment an adversary extracts your most sensitive information. In cloud-first environments, exfiltration often uses legitimate services and protocols that blend with normal traffic — making behavioural detection essential.

Coverage

Techniques covered
9
Detection rules
31
Cloud-specific
18

Threat context

How adversaries exfiltrate data

Modern exfiltration exploits the same cloud services your employees use every day: attackers copy S3 buckets to personal accounts, push sensitive code to GitHub, or upload files to personal cloud storage. Because these services are whitelisted, traditional perimeter controls miss the threat. The signal is in the volume and pattern, not the destination.

Double-extortion ransomware groups exfiltrate data before encrypting — they have data to sell regardless of whether the victim pays. This means exfiltration detection must precede the ransomware deployment phase. ManySignal's baseline-driven approach detects anomalous volume spikes before terabytes leave your environment.

Exfiltration: frequently asked questions

What is ATT&CK Exfiltration (TA0010)?

Exfiltration covers the techniques adversaries use to steal data from your environment. In double-extortion ransomware scenarios, exfiltration happens before encryption. In espionage campaigns, it may be the primary objective.

How does ManySignal detect exfiltration to legitimate cloud services?

ManySignal baselines normal data transfer volume per user and service. When a user uploads 10x their normal volume to Google Drive or copies large amounts of data to a personal Dropbox, ManySignal generates an alert correlated with the user's recent access and DLP policy events.

Can ManySignal detect DNS exfiltration?

Yes, when DNS query logs are ingested from Cloudflare, Cisco Umbrella, or similar sources. High-volume DNS queries to a single domain with long subdomains — a DNS tunnelling signature — trigger a detection correlated with the querying host's other activity.

Detect data theft before it becomes a headline

ManySignal's behavioural baselines detect anomalous data movement from cloud storage, SaaS apps, and network transfers in real time.