H3AD-REF / PLAYBOOKS / DATA EXFILTRATION ALERT

Leaving Is Normal.
Leaving Like This Isn't.

A static process reference for the alert that fires when data leaves somewhere it shouldn't. What commonly triggers it, how to work the triage in order, the signals that separate a real exfiltration event from a scheduled job nobody documented, and when legal and HR need to be in the room. Not a substitute for an org's own DLP policy or IR plan, just the reference. For unusual destination ports, see the Protocol & Port Reference.

Alert Overview

A data exfiltration alert can come from several different detection layers, and each one hands the analyst a different starting point. Knowing which one fired changes what to check first.

Common Trigger Sources

  • DLP content-match hit: a data loss prevention rule matched on file content, a classification tag, or a pattern such as a card number or a source-code signature
  • Unusual outbound data volume vs baseline: SIEM or NDR flags a host or user sending far more data outbound than their historical pattern
  • Cloud storage upload anomaly: a CASB or cloud DLP control flags an unusual upload volume or an unrecognized destination service
  • Removable media / USB transfer alert: an endpoint agent flags a large file copy to a USB device or an unapproved removable drive
  • Email with an unusually large attachment to an external domain: email security flags an outbound message leaving to a domain outside the org with a payload size well above normal

Initial Triage Steps

Work these in order. Most of what separates a real exfiltration event from a false alarm shows up in the first two steps, before the destination check even matters.

Triage Sequence

1. Identify what triggered it
├── A DLP content match, a volume threshold, or a destination reputation score
└── The trigger type tells you which log source has the most useful detail
    // a content match hands you the classification tag directly; a volume alert gives you none of that yet

2. Identify the user, host, and the data involved
├── Filenames, classification tags, and approximate size moved
└── Don't treat the alert's summary as complete, pull the underlying log event for the full file list
    // alert summaries frequently truncate to the first few filenames, and the rest is what determines severity

3. Identify the destination
├── External IP or domain, cloud storage service, personal email address, or USB device serial
└── Check the destination's reputation and ownership before assuming it's hostile
    // a surprising number of "unknown" destinations turn out to be an undocumented vendor

4. Check user context against their role
├── Is this expected for what they do? A scheduled backup job? An approved third-party integration?
└── Cross-reference against the change calendar and any approved-integration list before calling it anomalous

5. Check timing
├── After hours, immediately before a resignation date, or unusual relative to that specific user's own pattern
└── A timing anomaly rarely stands alone, pair it with the destination check above before escalating
    // a 2am transfer from a data engineer isn't the same signal as the same transfer from someone in finance

True Positive Indicators

Signals that push an alert toward a real exfiltration event, not a data point that stands on its own.

TRUE POSITIVE

Personal Cloud Or Webmail Destination [T1567.002]

No business relationship, no legitimate reason
The destination is personal cloud storage, a personal webmail account, or an unknown external IP with no business relationship on file. There's no scheduled job or vendor agreement that explains why data would go there.
TRUE POSITIVE

Sensitive Data, No Business Need

Classification without justification
The data carries a sensitive or confidential classification tag, and the user involved has no legitimate business need to access or move it. Role and data sensitivity should line up; when they don't, that gap is the signal.
TRUE POSITIVE

Staged By Bulk Access First

The transfer is rarely the first step
The transfer was preceded by unusual access patterns: mass file access across shares, a database export, or a bulk download shortly before the data left. Actors and insiders alike tend to gather before they move.
TRUE POSITIVE

Departing Or Under Investigation

Context that changes everything about the same alert
The user recently resigned, was terminated, or is subject to an active HR investigation. The same transfer volume that's routine for a tenured employee reads very differently on someone's way out the door.
TRUE POSITIVE

Files Renamed, Archived, Or Encrypted Pre-Transfer

Staging behavior meant to dodge content inspection
Files were encrypted, zipped into an archive, or renamed shortly before the transfer. This is a deliberate attempt to defeat content-matching DLP rules, and it rarely happens by accident.

False Positive Indicators

Context that explains the same alert without an incident behind it. Check these before escalating, not after.

FALSE POSITIVE

Known Scheduled Job

Matches a backup or replication schedule to an approved destination
The transfer matches a known, scheduled backup or replication job going to a destination that's already documented and approved. Check the change calendar before treating a recurring pattern as new.
FALSE POSITIVE

Approved SaaS Or Cloud Integration

A business-sanctioned sync job, not an unauthorized transfer
The transfer is a business-approved SaaS or cloud integration, such as an approved CRM sync job moving customer records to a vendor platform on a regular schedule.
FALSE POSITIVE

Role Legitimately Involves Bulk Transfer

Data engineers and backup administrators move large volumes as their job
The user's role legitimately involves moving bulk data as a normal part of the job, such as a data engineer running an ETL pipeline or a backup administrator managing replication.
FALSE POSITIVE

Approved Partner Or Vendor Range

Destination is documented, not discovered
The destination IP matches an approved partner or vendor IP range already on file. Confirm against the current list rather than an old one, since vendor infrastructure changes more often than that list gets updated.

Escalation Criteria

The thresholds where this stops being a purely technical decision and needs other people in the loop before the next action.

ESCALATE

Confirmed Sensitive Data Left Unapproved

Escalate to the IR lead and legal/privacy immediately
PII, intellectual property, or financial records are confirmed to have left through a channel that isn't approved. This goes to the IR lead and legal or privacy immediately, not at the end of the shift.
ESCALATE

Exceeds DLP Policy Threshold

Volume or classification, either one is enough
The volume moved or the data classification involved exceeds the org's DLP policy threshold for automatic escalation, independent of whether the destination looks suspicious on its own.
ESCALATE

Insider-Threat Indicators Present

Loop in HR and Legal before any user-facing action
Indicators like a recent resignation or an active HR case are present alongside the transfer. HR and Legal need to be looped in before anyone takes a user-facing action, including a simple account lockout.

Containment Actions

What to actually do once an alert is confirmed as a true positive, in an order that limits further loss without destroying evidence.

CONTAIN

Disable The Account, Revoke Sessions

Only where malicious intent is suspected
Disable the user account and revoke active session tokens if malicious intent is suspected. This stops further transfer immediately, but treat it as a decision point, not a reflex, once insider-threat criteria apply above.
CONTAIN

Block The Destination

Proxy and firewall, not just one or the other
Block the destination IP or domain at the proxy and the firewall. This closes the specific channel used without waiting on a broader network change.
CONTAIN

Preserve Evidence First

Before any further remediation step
Preserve DLP logs, network flow data, and endpoint artifacts before taking further remediation action. Remediating first is how the evidence needed for the HR or legal case afterward gets lost.
CONTAIN

Coordinate Before Confronting

Insider cases carry real legal exposure
If this is an insider case, coordinate with HR and Legal before confronting the user. Mishandling this one step, acting alone or moving too fast, creates real legal exposure for the organization.