Case 250258 · Blue team / DFIR · L5 Expert
Proving What Was Exfiltrated
Practise as: Deep dive · Explain it
- 01 Context
- 02 Mechanism
- 03 Lessons
What a strong answer covers
Try it out loud first. Then check yourself:
- Notification depends on what left, not just what was reachable; missing logs are not evidence that nothing left.
- Staging: archivers (7z, rar) in Prefetch/Amcache, and $UsnJrnl records of archives created then deleted.
- Transfer: SRUM per-process bytes sent, proxy/firewall byte counts, and tool traces such as rclone configs or MEGA endpoints.
- SaaS/cloud: M365 MailItemsAccessed, SharePoint FileDownloaded, S3 data events; check each was licensed/enabled before the incident.
- Bound the dataset by comparing egress volume to staged archive sizes; leak-site samples can confirm specific files.
If the interviewer pushes back
- Egress went over TLS to a cloud storage provider and you only have NetFlow. How confidently can you scope it, and how do you word that for legal?
Go deeper
cardosec draws a security topic and gives you a clock: explain it out loud with no notes, then see what you covered and what you missed. Free during early access.