Leaving Is Normal.
Leaving Like This Isn't.
A static process reference for the alert that fires when data leaves somewhere it shouldn't. What commonly triggers it, how to work the triage in order, the signals that separate a real exfiltration event from a scheduled job nobody documented, and when legal and HR need to be in the room. Not a substitute for an org's own DLP policy or IR plan, just the reference. For unusual destination ports, see the Protocol & Port Reference.
Alert Overview
A data exfiltration alert can come from several different detection layers, and each one hands the analyst a different starting point. Knowing which one fired changes what to check first.
Common Trigger Sources
- DLP content-match hit: a data loss prevention rule matched on file content, a classification tag, or a pattern such as a card number or a source-code signature
- Unusual outbound data volume vs baseline: SIEM or NDR flags a host or user sending far more data outbound than their historical pattern
- Cloud storage upload anomaly: a CASB or cloud DLP control flags an unusual upload volume or an unrecognized destination service
- Removable media / USB transfer alert: an endpoint agent flags a large file copy to a USB device or an unapproved removable drive
- Email with an unusually large attachment to an external domain: email security flags an outbound message leaving to a domain outside the org with a payload size well above normal
Initial Triage Steps
Work these in order. Most of what separates a real exfiltration event from a false alarm shows up in the first two steps, before the destination check even matters.
Triage Sequence
1. Identify what triggered it ├── A DLP content match, a volume threshold, or a destination reputation score └── The trigger type tells you which log source has the most useful detail // a content match hands you the classification tag directly; a volume alert gives you none of that yet 2. Identify the user, host, and the data involved ├── Filenames, classification tags, and approximate size moved └── Don't treat the alert's summary as complete, pull the underlying log event for the full file list // alert summaries frequently truncate to the first few filenames, and the rest is what determines severity 3. Identify the destination ├── External IP or domain, cloud storage service, personal email address, or USB device serial └── Check the destination's reputation and ownership before assuming it's hostile // a surprising number of "unknown" destinations turn out to be an undocumented vendor 4. Check user context against their role ├── Is this expected for what they do? A scheduled backup job? An approved third-party integration? └── Cross-reference against the change calendar and any approved-integration list before calling it anomalous 5. Check timing ├── After hours, immediately before a resignation date, or unusual relative to that specific user's own pattern └── A timing anomaly rarely stands alone, pair it with the destination check above before escalating // a 2am transfer from a data engineer isn't the same signal as the same transfer from someone in finance
True Positive Indicators
Signals that push an alert toward a real exfiltration event, not a data point that stands on its own.
Personal Cloud Or Webmail Destination [T1567.002]
Sensitive Data, No Business Need
Staged By Bulk Access First
Departing Or Under Investigation
Files Renamed, Archived, Or Encrypted Pre-Transfer
False Positive Indicators
Context that explains the same alert without an incident behind it. Check these before escalating, not after.
Known Scheduled Job
Approved SaaS Or Cloud Integration
Role Legitimately Involves Bulk Transfer
Approved Partner Or Vendor Range
Escalation Criteria
The thresholds where this stops being a purely technical decision and needs other people in the loop before the next action.
Confirmed Sensitive Data Left Unapproved
Exceeds DLP Policy Threshold
Insider-Threat Indicators Present
Containment Actions
What to actually do once an alert is confirmed as a true positive, in an order that limits further loss without destroying evidence.