PHASE: Exfiltration Indicators50% COMPLETION
Abort Mission
MODULE 12

Data Exfiltration Hunting

Detecting large data transfers, DNS tunneling, and cloud storage uploads.

Exfiltration Indicators

Data exfiltration is the final stage of many attacks.

Large Uploads: Unusual outbound traffic volume
DNS Tunneling: Abnormally long DNS queries
Cloud Storage: Uploads to Dropbox/Google Drive