Open cardosec

Case 250258 · Blue team / DFIR · L5 Expert

Proving What Was Exfiltrated

Practise as: Deep dive · Explain it
  1. 01 Context
  2. 02 Mechanism
  3. 03 Lessons
What a strong answer covers

Try it out loud first. Then check yourself:

  1. Notification depends on what left, not just what was reachable; missing logs are not evidence that nothing left.
  2. Staging: archivers (7z, rar) in Prefetch/Amcache, and $UsnJrnl records of archives created then deleted.
  3. Transfer: SRUM per-process bytes sent, proxy/firewall byte counts, and tool traces such as rclone configs or MEGA endpoints.
  4. SaaS/cloud: M365 MailItemsAccessed, SharePoint FileDownloaded, S3 data events; check each was licensed/enabled before the incident.
  5. Bound the dataset by comparing egress volume to staged archive sizes; leak-site samples can confirm specific files.

If the interviewer pushes back

  • Egress went over TLS to a cloud storage provider and you only have NetFlow. How confidently can you scope it, and how do you word that for legal?

Go deeper

cardosec draws a security topic and gives you a clock: explain it out loud with no notes, then see what you covered and what you missed. Free during early access.