Sunday 12 July 2026 17:25:29 GMT+02:00

Netcrook

HomeManifesto
News
Techcrook
Geocrook
WikicrookTeamAppContactLogin
EnglishItaliano

WIKICROOK

Exfiltration

The unauthorized transfer of data out of a network or system.

Exfiltration is the unauthorized transfer of data out of a network, device, or application. Attackers exfiltrate files, database records, credentials, or email to steal sensitive information before a victim notices. It matters because once data leaves the environment, it can be copied, sold, leaked, or used for follow-on attacks such as extortion, fraud, or identity theft.

In real attacks, exfiltration often happens after initial access and privilege escalation. Common signs include unusual outbound traffic, large archive uploads, remote transfers to unknown hosts, suspicious cloud-storage use, or encoded traffic hidden in normal protocols. Defenders look for these patterns with network monitoring, data loss prevention tools, endpoint alerts, and access logs. In ransomware cases, exfiltration is especially important because attackers may threaten to publish stolen data even if backups restore systems.

← WIKICROOK index