166 terms · 75/46/45
Technique № 031 · class: exfiltration / impact

Data Exfiltration

Data exfiltration involves transferring stolen information from the compromised environment to an attacker-controlled location. Data can be sent through encrypted channels, legitimate cloud services, email, or even physical media.

Term

description · examples · notes

Data exfiltration involves transferring stolen information from the compromised environment to an attacker-controlled location. Data can be sent through encrypted channels, legitimate cloud services, email, or even physical media.

Description

Attackers often compress and encrypt data before sending to evade data loss prevention systems. Exfiltration can be a one-time event or gradual, spread over an extended period.

Examples

  • Uploading compressed archives of internal documents to a cloud storage service
  • Gradually exfiltrating a database in small segments through an encrypted channel
  • Using DNS queries to incrementally encode and send stolen data
  • Copying data to removable media physically taken out of the organization

Notes

  • Monitoring unusually large outbound transfers and mass data access helps with early detection.

Mentioned in the news

Composite

Threats

used by 21

Defenses

countered by 12