Exfiltration
Data exfiltration is the moment an adversary extracts your most sensitive information. In cloud-first environments, exfiltration often uses legitimate services and protocols that blend with normal traffic — making behavioural detection essential.
Coverage
- Techniques covered
- 9
- Detection rules
- 31
- Cloud-specific
- 18
Threat context
How adversaries exfiltrate data
Modern exfiltration exploits the same cloud services your employees use every day: attackers copy S3 buckets to personal accounts, push sensitive code to GitHub, or upload files to personal cloud storage. Because these services are whitelisted, traditional perimeter controls miss the threat. The signal is in the volume and pattern, not the destination.
Double-extortion ransomware groups exfiltrate data before encrypting — they have data to sell regardless of whether the victim pays. This means exfiltration detection must precede the ransomware deployment phase. ManySignal's baseline-driven approach detects anomalous volume spikes before terabytes leave your environment.
Exfiltration techniques ManySignal detects
Exfiltration Over Web Service
Data uploaded to S3, Google Drive, GitHub, or webhook endpoints outside the organisation.
Data from Cloud Storage
Bulk download or cross-account copy of S3 objects, Azure blobs, or GCS buckets.
Transfer Data to Cloud Account
Copying data to attacker-controlled cloud accounts before removal.
Exfiltration Over Alternative Protocol
DNS tunnelling, ICMP exfiltration, or non-standard ports used to bypass egress controls.
Exfiltration Over C2 Channel
Data tunnelled through an existing command-and-control channel.
Exfiltration: frequently asked questions
What is ATT&CK Exfiltration (TA0010)?
Exfiltration covers the techniques adversaries use to steal data from your environment. In double-extortion ransomware scenarios, exfiltration happens before encryption. In espionage campaigns, it may be the primary objective.
How does ManySignal detect exfiltration to legitimate cloud services?
ManySignal baselines normal data transfer volume per user and service. When a user uploads 10x their normal volume to Google Drive or copies large amounts of data to a personal Dropbox, ManySignal generates an alert correlated with the user's recent access and DLP policy events.
Can ManySignal detect DNS exfiltration?
Yes, when DNS query logs are ingested from Cloudflare, Cisco Umbrella, or similar sources. High-volume DNS queries to a single domain with long subdomains — a DNS tunnelling signature — trigger a detection correlated with the querying host's other activity.
Detect data theft before it becomes a headline
ManySignal's behavioural baselines detect anomalous data movement from cloud storage, SaaS apps, and network transfers in real time.